Password spraying campaign targets AWS root user accounts across 150+ organizations
Datadog researchers observed a password spraying campaign attempting to authenticate as AWS root users across 150+ organizations.
Datadog Security Research observed a large-scale password spraying campaign attempting to authenticate as AWS root user accounts across more than 150 organizations. The campaign targeted root credentials rather than standard IAM users, and no confirmed compromises are stated in the report. Root account access would grant full control of affected AWS environments, making this a significant credential-attack campaign for cloud defenders.