Unauthorized Account Removals from AWS Organizations Exploited by Threat Actors

Unauthorized Account Removals from AWS Organizations Exploited by Threat Actors

First seen 19 May 2026, 22:19 UTC Aws.Amazonaws-samples.github.io 88% similarity 69.0

Article Content

Browse articles
ThreatCluster

Threat actors are exploiting AWS Organizations by using compromised credentials to remove accounts from organizations. This tactic allows them to bypass Service Control Policies (SCPs) and gain unrestricted access to resources. The attack begins with the use of the organizations:LeaveOrganization permission, which enables the removal of a member account from the organization. Once removed, the account loses the protections and visibility provided by the organization, including billing alerts and CloudTrail logging. This can lead to significant data exposure and operational risks for affected organizations. The AWS Customer Incident Response Team has identified this trend and recommends implementing SCPs to deny the organizations:LeaveOrganization action as a preventive measure. Organizations are urged to investigate any unexpected LeaveOrganization API calls in their CloudTrail logs.

Key Points: • Threat actors exploit AWS Organizations by removing accounts to bypass security controls. • The attack leverages the organizations:LeaveOrganization permission to gain unrestricted access. • Implementing Service Control Policies can help prevent unauthorized account removals.

ThreatCluster AI

Timeline

2026-05-19
AWS CIRT reports on account removal tactic
AWS Customer Incident Response Team highlights a new threat where accounts are removed from AWS Organizations, compromising security.
Aws.Amazon
2026-05-19
Threat technique catalog entry created
A new entry in the AWS threat technique catalog details the Leave AWS Organization tactic used by threat actors.
aws-samples.github.io

Community

Browse all →