My AWS account was breached, wracked up a few thousand in charges via EC2 (c5.xlarge instances) and snapshots, in various regions.
Support got a hold of me to let me know (thanks), but they couldn't get rid of the unauthorized instances themselves - so frustrating.
Support got a hold of me to let me know (thanks), but they couldn't get rid of the unauthorized instances themselves - so frustrating.
So spent the morning going through all regions, all services, checking for unauthorized use over the phone with support

Security is only going to be a bigger issue in the future.
It felt backwards knowing they had proactive preventions in place, but I *still* had to do reactive work, manually slogging through UI to secure my account.
It felt backwards knowing they had proactive preventions in place, but I *still* had to do reactive work, manually slogging through UI to secure my account.
In other thoughts: can't help but wonder what the unauthorized person was doing with those instances... bitcoin mining? Minecraft severs?
(but seriously, any ideas? ~15 C5 w/ 8gb storage seems like an exceptional use.)

(but seriously, any ideas? ~15 C5 w/ 8gb storage seems like an exceptional use.)