INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
AWS Keys Compromised in Amazon Bedrock Access Testing Vulnerability
| 2026-10-10 02:00 DATA BREACH
Executive Summary
AI-generated
On October 10, 2026, attackers exploited exposed AWS keys to test for Amazon Bedrock access, using API calls like GetSendQuota and GetSMSAttributes to assess account environments and sending limits. The attackers' goal was likely to determine the usefulness of captured credentials, as this affects their resale value. Metrics revealed by the attack included IP addresses associated with compromised accounts, such as [IOC HIDDEN • LOGIN REQUIRED], [IOC HIDDEN • LOGIN REQUIRED], [IOC HIDDEN • LOGIN REQUIRED], and others, totaling over a dozen unique IP addresses. The attackers targeted Amazon Bedrock, an AWS service, using API calls to assess account status and sending limits. As of the reported incident, no further information is available on the current status or aftermath of this attack.
Technical Mitigations AI-generated
• Use a secure AWS key rotation policy to limit the validity of exposed credentials.
• Implement API call rate limiting for GetSendQuota, GetSMSAttributes, and GetSMSSandboxAccountStatus to detect excessive testing activity.
• Block or hunt for IP addresses associated with Amazon Bedrock access attempts.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
94.154.•••.•••
78.109.•••.•••
112.78.•••.•••
151.243.•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
Global Scope
Incident Timeline
Intelligence Sources
AlienVault OTX
2026-10-10