Aws.Amazon
Unauthorized Account Removals from AWS Organizations Exploited by Threat Actors
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Threat actors are exploiting AWS Organizations by using compromised credentials to remove accounts from organizations. This tactic allows them to bypass Service Control Policies (SCPs) and gain unrestricted access to resources. The attack begins with the use of the organizations:LeaveOrganization permission, which enables the removal of a member account from the organization. Once removed, the account loses the protections and visibility provided by the organization, including billing alerts and CloudTrail logging. This can lead to significant data exposure and operational risks for affected organizations. The AWS Customer Incident Response Team has identified this trend and recommends implementing SCPs to deny the organizations:LeaveOrganization action as a preventive measure. Organizations are urged to investigate any unexpected LeaveOrganization API calls in their CloudTrail logs.
Key Points: • Threat actors exploit AWS Organizations by removing accounts to bypass security controls. • The attack leverages the organizations:LeaveOrganization permission to gain unrestricted access. • Implementing Service Control Policies can help prevent unauthorized account removals.