Attackers Target AWS Root Accounts at 150+ Organizations with Password Spraying
Key Takeaways A password spraying campaign targeted AWS root accounts across more than 150 organizations between July 24 and August 23, 2026. Attackers used common passwords against numerous accounts...
Key Takeaways
- A password spraying campaign targeted AWS root accounts across more than 150 organizations between July 24 and August 23, 2026.
- Attackers used common passwords against numerous accounts to avoid triggering lockouts, but no successful compromises were observed.
- The campaign highlights the critical importance of robust security measures for AWS root accounts, including Multi-Factor Authentication (MFA).
- Threat actors likely obtained root account email addresses through various reconnaissance methods.
Attackers Target AWS Root Accounts with Password Spraying Campaign
A recent password spraying campaign has set its sights on AWS root accounts, impacting over 150 organizations. Between July 24 and August 23, 2026, Datadog Security Research documented a surge in failed console login attempts targeting these highly privileged identities, as detailed in a report by Datadog researchers said.
Table Of Content
The Allure of AWS Root Accounts
The AWS root user represents the primary identity established during the initial registration of an AWS account. This account possesses unfettered access to all cloud resources, account configurations, billing details, and critical administrative functionalities. A successful compromise of a root account could grant an adversary comprehensive control over an organization’s entire AWS infrastructure, posing a significant security risk.
Datadog’s analysis revealed that while the campaign targeted a large number of organizations, most experienced a relatively low volume of login attempts. The median number of failed login attempts per organization was two, though some victims observed up to eight attempts during the month-long period. Crucially, researchers found no evidence of successful authentications, indicating that the campaign did not result in confirmed AWS account compromises.
Password Spraying Tactics and Obfuscation
The attackers employed password spraying, a technique where threat actors systematically attempt a limited selection of common or previously exposed passwords across a wide array of accounts. This strategy is designed to circumvent account lockout mechanisms that typically activate during more aggressive, single-account brute-force attacks.
Observations linked two distinct browser user-agent strings to the malicious activity. One mimicked an older Microsoft Edge browser, specifically Chrome version 85, while the other impersonated Firefox version 120. Although these identifiers could assist defenders in reviewing logs for suspicious authentication attempts, it’s important to note that user-agent values are easily spoofed by attackers.
To further obscure their origins, the campaign utilized a proxy infrastructure. Source IP addresses were distributed across numerous countries and autonomous systems, rendering geographical blocking measures less effective. Threat intelligence services identified this infrastructure as comprising hosting services, residential proxies, or similar systems commonly used to mask the true source of malicious traffic.
The targeted organizations did not exhibit a discernible pattern, spanning various industries and geographical locations. This suggests that the attackers likely leveraged an extensive list of potential AWS account email addresses rather than concentrating on a specific sector. The campaign’s requirement for AWS root console login attempts to use the account’s email address implies that attackers may have acquired these email addresses through data breaches, public records, phishing schemes, or other reconnaissance efforts. Alternatively, the attackers might have tested a vast number of corporate email addresses until valid AWS root identities were identified.
Enhanced Protections for Root Accounts
AWS root accounts remain exceptionally sensitive targets due to their unique ability to perform actions unavailable to standard IAM users. Recognizing this, AWS has implemented stronger protective measures for root accounts. Since June 2025, AWS IAM has mandated multi-factor authentication (MFA) for root users across all account types, with a 35-day grace period following the initial console sign-in attempt. While MFA is a powerful deterrent against account takeover, even if a password is compromised, organizations should consider it one component of a comprehensive security strategy.
What You Should Do
- Review AWS CloudTrail logs for root-level
ConsoleLoginevents, paying close attention to failed attempts, especially those originating from the identified Chrome/Edge and Firefox user agents. - Implement alerts for direct root sign-ins, root API activity, changes to root credentials, and any unusual privileged sessions.
- Minimize the routine use of root credentials. Where possible, enable centralized root access and enforce Service Control Policies (SCPs) that restrict direct root activity in member accounts.
- Protect management-account root credentials with strong, phishing-resistant hardware MFA devices.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.