At a glance
| Actor or group | Unidentified threat actors |
| Activity type | Password spraying |
| Targets or victims | AWS root user accounts at 150+ organizations |
| Scale | Median of two attempts per target |
| Law-enforcement status | Active security research |
| Source | Datadog Security Research |
Security researchers discovered an active AWS password spraying campaign targeting highly privileged cloud accounts. Attackers attempted to compromise root user logins across multiple industries globally. Fortunately, telemetry indicates no successful authentication events during the observation window.
How the AWS Password Spraying Works
Datadog observed this coordinated attack occurring between July 24 and August 23, 2026. The official report states that “during this period, attackers made repeated failed authentication attempts against AWS root user accounts at more than 150 organizations.”
Generating a failed console login request requires a valid root email address. Consequently, the attackers either possessed a list of targeted emails or systematically brute forced through known addresses. Furthermore, the threat actors routed their authentication requests through global residential proxies. They also utilized specific Chrome and Firefox user agents to disguise their traffic. This distributed approach helps this AWS password spraying activity bypass simple geographic blocking filters.
Suspected Attackers and Targets
The exact identity of the threat group remains unconfirmed. Analysts noted that targeted organizations show no clear victimology, varying widely by country and industry. The report states, “We have not observed a successful authentication attempt, so we cannot determine the attacker’s intent.”
Scale of the Cloud Attacks
While the overall volume remains low per target, the breadth is significant. The research notes that “organizations saw a median of two attempts each, with some experiencing up to eight attempts across the campaign window.” AWS root user accounts possess complete access to billing and core account settings. A successful breach would grant attackers total control.
Protecting Root User Accounts
Since June 2025, cloud providers enforced multi-factor authentication for root users across all account types. However, organizations must not rely on authentication safeguards alone. Administrators should reduce their dependence on persistent root credentials entirely.
Security teams can deploy service control policies to prevent direct root activity within member accounts. Additionally, organizations should treat all root activity as security-relevant.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!