logo

Cybercrime Gangs Abscond With Thousands of Orgs' AWS Credentials

ID: 03d7e6eb-690c-55dd-aa49-8b7c7fdee878

STIX ID: report--03d7e6eb-690c-55dd-aa49-8b7c7fdee878

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2024-12-10

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Researchers uncovered a mass cybercrime campaign in which attackers scanned millions of public web endpoints to find and exploit application-side vulnerabilities and misconfigurations in AWS-hosted assets, harvesting AWS keys, infrastructure credentials, source code, databases and other secrets from thousands of organizations; the operation used automated tooling (including Shodan lookups and product-specific endpoint extraction), has ties to Nemesis/ShinyHunters, and was partially exposed when the attackers stored stolen data and tools in a misconfigured 2TB S3 bucket, which researchers reported to AWS and Israeli authorities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.