Cybercrime Gangs Abscond With Thousands of Orgs' AWS Credentials
ID: 03d7e6eb-690c-55dd-aa49-8b7c7fdee878
STIX ID: report--03d7e6eb-690c-55dd-aa49-8b7c7fdee878
Feed Name: Dark Reading
Date Published: 2024-12-10
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Researchers uncovered a mass cybercrime campaign in which attackers scanned millions of public web endpoints to find and exploit application-side vulnerabilities and misconfigurations in AWS-hosted assets, harvesting AWS keys, infrastructure credentials, source code, databases and other secrets from thousands of organizations; the operation used automated tooling (including Shodan lookups and product-specific endpoint extraction), has ties to Nemesis/ShinyHunters, and was partially exposed when the attackers stored stolen data and tools in a misconfigured 2TB S3 bucket, which researchers reported to AWS and Israeli authorities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
