logo

CIRT insights: How to help prevent unauthorized account removals from AWS Organizations

ID: 671e2898-1ce3-530b-8eba-ba95c06e362a

STIX ID: report--671e2898-1ce3-530b-8eba-ba95c06e362a

Feed Name: AWS Security Blog

Threat Score
70/100

Date Published: 2026-05-19

Date Updated: 2026-05-19

Author: Shannon Brazil

...
...

This AWS Customer Incident Response Team advisory describes a tactic where threat actors leverage the organizations:LeaveOrganization permission/API to remove a member account from an AWS Organization, which eliminates inherited guardrails (SCPs), centralized logging and detection (CloudTrail, GuardDuty), and consolidated billing—reducing visibility and hampering incident response; the report outlines associated CloudTrail events to detect the activity and recommends mitigations such as a DenyLeaveOrganization SCP, least-privilege IAM, MFA on root, and centralized root access management.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.