Skip to content
Threat Actors Exploit AWS Cognito Refresh Tokens for Persistent Access

Threat Actors Exploit AWS Cognito Refresh Tokens for Persistent Access

First seen 28 Apr 2026, 19:34 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster April 29, 2026 at 19:05 UTC
  • Threat actors exploit long-lived Amazon Cognito refresh tokens for persistent access.
  • Initial access is often gained through credential theft or compromised storage.
  • AWS recommends enabling refresh token rotation to mitigate this risk.

In April 2026, AWS reported that threat actors are exploiting Amazon Cognito refresh tokens to maintain unauthorized access to applications. These tokens, which can be valid for up to 10 years, allow attackers to generate new access tokens without re-authenticating. The initial access is typically gained through credential theft or compromised client-side storage. This method enables attackers to remain undetected while continuing to access resources even after the original access tokens expire. The AWS Cyber Incident Response Team (CIRT) noted that environments without refresh token rotation are particularly vulnerable, as the same token can be reused indefinitely. Additionally, threat actors have been observed deregistering Amazon Machine Images (AMIs) to hinder recovery efforts. The updates to the Threat Technique Catalog (TTC) include new methods for detecting these activities and recommendations for mitigation.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 134d ago How this analysis works

Timeline

2026-04-28
AWS CIRT reports on exploitation of Cognito refresh tokens.
2026-04-28
AWS updates Threat Technique Catalog with new detection methods.

More articles in this cluster (6)

Following this threat?

Track AWS in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed