Established 2026Sunday, 6 September 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageThreat Intel Desk
Threat Intel

Password spraying campaign targets AWS root user accounts across 150+ organizations

Datadog documents a password-spraying campaign hitting AWS root accounts across 150+ organisations — a reminder that the most privileged cloud identity is often the least protected.

Summary written by editorial AI · Source link below

Filed by Datadog Security Labs1 min readRead at source ↗

Datadog Security Research observed a password spraying campaign attempting to authenticate as the AWS root user across more than 150 organizations.

Editorial Analysis

Why it matters

AWS root accounts carry unrestricted power and are frequently exempt from conditional-access policies; large-scale spraying campaigns exploit this systemic gap.

What to do

Enforce hardware MFA on every AWS root account, enable root-login CloudTrail alerts, and restrict root credentials to physical safes or secrets vaults.

Board brief

Attackers are systematically spraying passwords against the most powerful AWS account type across hundreds of organisations — root-account MFA enforcement is non-negotiable.

Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.

Continue at the source
Read the full report at Datadog Security Labs

External link — opens at Datadog Security Labs in a new tab.

§
Continue with

More from the Threat Intel Desk