securityonline.info 9/4/2026, 9:16:36 AM · external

AWS Password Spraying Campaign Targets Root Accounts

AWS Password Spraying Campaign Targets Root Accounts

THE page discusses an active AWS password spraying campaign targeting root user accounts across over 150 organizations. Important details include:

1. **Threat Overview**: Unidentified actors conducted a systematic effort to compromise AWS root logins; however, no successful authentications were reported.

2. **Attack Methodology**: The attackers made use of global residential proxies and emulated browser user agents to hide their activity, making it harder to detect.

3. **Campaign Scale**: The median number of failed login attempts per organization was two, with some organizations experiencing as many as eight attempts.

4. **Security Recommendations**: Organizations are urged to implement multi-factor authentication and reduce reliance on root account access, while monitoring all root activity as security-critical.

View full article

Article by CyberSIXT