ThreatCluster

Password Spraying Attacks Target AWS Root Accounts at 150+ Organizations

First seen 1 Sep 2026, 09:29 UTC CybersecuritynewsGbhackers 57

Article Content

Browse articles
ThreatCluster

A password-spraying campaign has been identified targeting AWS root user accounts across more than 150 organizations. This campaign occurred from July 24 to August 23, 2026, involving multiple failed login attempts against these highly privileged accounts. The AWS root user is the primary identity created during account registration, granting unrestricted access to cloud resources. Organizations affected by this attack are urged to enhance their security measures to protect against unauthorized access. The attack method exploits weak password policies and the lack of multi-factor authentication. Current status indicates that the campaign has been ongoing, but no specific remediation steps or tools have been detailed in the articles. Security teams are advised to monitor their AWS accounts closely for unusual login attempts.

Key Points: • Over 150 organizations targeted in a password-spraying campaign against AWS root accounts. • Attack occurred from July 24 to August 23, 2026, involving multiple failed login attempts. • Organizations are advised to enhance security measures, including implementing multi-factor authentication.

Timeline

2026-07-24
Password-spraying campaign began
Attackers initiated multiple failed login attempts against AWS root accounts at various organizations.
Gbhackers
2026-08-23
Password-spraying campaign ended
The campaign concluded with numerous failed authentication attempts recorded across affected organizations.
Gbhackers
2026-09-01
Reports published
Cybersecurity outlets reported on the ongoing password-spraying campaign targeting AWS accounts.
Cybersecuritynews