AWS Hacked in Under 10 Minutes: How AI-Assisted Attacks Are Changing Cybersecurity (2026)

A recent security breach on AWS showcases the alarming capabilities of AI-assisted cyberattacks. Researchers observed a digital intruder swiftly gaining administrative access in under 10 minutes, highlighting the growing threat of AI-driven attacks. The Sysdig Threat Research Team noted the attack's speed and the use of large language models (LLMs) for automation, from reconnaissance to malicious code writing and LLMjacking. The threat actor compromised 19 AWS principals, abused Bedrock models, and utilized GPU compute resources, indicating a sophisticated and well-coordinated operation. The attack began with stolen credentials from public Amazon S3 buckets, which contained sensitive data and Retrieval-Augmented Generation (RAG) data for AI models. The attacker's code, written in Serbian, listed IAM users and their access keys, and included comprehensive exception handling. The use of non-existent GitHub repository references and LLM-generated code with Serbian comments further pointed to AI assistance. The intruder then attempted to assume OrganizationAccountAccessRole, including non-victim organization account IDs, a behavior consistent with AI hallucinations. The attacker gained access to sensitive data, including secrets, SSM parameters, CloudWatch logs, and internal data from S3 buckets. The LLMjacking phase involved accessing cloud-hosted LLMs, with the attacker abusing Amazon Bedrock access to invoke multiple models. Sysdig recommends measures such as restricting permissions, enabling logging, and hardening identity security to defend against similar intrusions, emphasizing the need for proactive security measures in the face of evolving AI-driven threats.

AWS Hacked in Under 10 Minutes: How AI-Assisted Attacks Are Changing Cybersecurity (2026)
Top Articles
Latest Posts
Recommended Articles
Article information

Author: Van Hayes

Last Updated:

Views: 6118

Rating: 4.6 / 5 (46 voted)

Reviews: 85% of readers found this page helpful

Author information

Name: Van Hayes

Birthday: 1994-06-07

Address: 2004 Kling Rapid, New Destiny, MT 64658-2367

Phone: +512425013758

Job: National Farming Director

Hobby: Reading, Polo, Genealogy, amateur radio, Scouting, Stand-up comedy, Cryptography

Introduction: My name is Van Hayes, I am a thankful, friendly, smiling, calm, powerful, fine, enthusiastic person who loves writing and wants to share my knowledge and understanding with you.