Hackers Target AWS Root Accounts at 150+ Organizations in Password
Datadog Security Research observed a password-spraying campaign targeting AWS root accounts at more than 150 organizations between July 24 and August 23, 2026, with repeated failed console login attempts against highly privileged identities. The AWS root user is the original identity created when an AWS account is registered. It has unrestricted access to cloud resources, […]
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
