HomeTopics 2Cloud SecurityAWS Root Accounts Targeted in Password-Spraying Campaign Across More Than 150 Organizations

AWS Root Accounts Targeted in Password-Spraying Campaign Across More Than 150 Organizations

Date:

Related stories

spot_imgspot_imgspot_imgspot_img

Attackers are increasingly targeting the most powerful identities in cloud environments. A newly uncovered campaign targeting AWS root accounts is a timely reminder that privileged access remains one of cybersecurity’s most valuable – and vulnerable – targets.

Security researchers at Datadog Security Labs say they observed a password-spraying campaign targeting AWS root user accounts across more than 150 organizations between July 24 and August 23, 2026. While researchers have not observed a successful authentication, the campaign is a timely warning: attackers are still willing to go after the most privileged account in an AWS environment.

For organizations operating critical workloads in the cloud, this matters. An AWS root account is not an ordinary user account. It has complete access to the account and can perform sensitive actions that other identities cannot. A successful compromise could potentially give an attacker extraordinary control over cloud resources, billing and account settings.

The campaign also highlights a broader reality in cybersecurity: identity remains one of the most attractive attack surfaces.

More Than 150 Organizations in the Attackers’ Crosshairs

According to Datadog Security Labs, attackers repeatedly attempted to authenticate against AWS root user accounts at more than 150 organizations during the month-long campaign.

The activity was not a conventional high-volume brute-force attack. Instead, it resembled password spraying a technique in which attackers try a limited number of passwords across many accounts to reduce the likelihood of triggering traditional lockout mechanisms.

Datadog observed a median of two authentication attempts per targeted organization, while some organizations received up to eight attempts during the campaign window.

Researchers identified two notable technical fingerprints associated with the activity: Chrome and Firefox user-agent strings, along with proxy infrastructure used to tunnel authentication requests. The source IP addresses were spread across multiple countries and autonomous systems, with threat intelligence sources identifying the infrastructure as hosting services, residential proxies or similar services.

Perhaps more concerning is the lack of a clear pattern in the victims. Datadog said the targeted organizations span multiple industries and countries, with no obvious victimology.

That makes the campaign difficult to classify as a narrowly targeted espionage operation or a sector-specific attack.

Why the AWS Root User Is Such a Valuable Target

The AWS root user is created when an AWS account is registered and represents the highest-privilege identity within that account.

It has complete access to AWS resources, billing information and account settings, including certain operations that cannot be performed by other identities. AWS itself strongly recommends that organizations avoid using the root user for everyday tasks.

That level of privilege makes the root account an attractive target.

If attackers gain control of a highly privileged identity, the consequences can extend far beyond one compromised application or server. Identity compromise can become a gateway to wider cloud operations, credential changes, infrastructure manipulation and access to sensitive business data.

However, targeting the root account is not necessarily the easiest route into an AWS environment.

AWS says MFA is required for root users across standalone, management and member accounts, with a 35-day grace period associated with the first console sign-in attempt when MFA has not yet been configured.

AWS also recommends stronger phishing-resistant authentication methods, including passkeys and security keys based on FIDO standards.

So why target the root account at all?

For attackers, high-value identities can justify additional effort.

The Email Address Question Adds Another Layer of Concern

One of the most interesting findings in Datadog’s investigation involves the mechanics of the attack.

A failed AWS root ConsoleLogin attempt requires the email address associated with the root account. This means the attacker may already have possessed a list of AWS root email addresses or may have been testing account email addresses to identify valid targets.

Datadog has not identified the attacker’s motive and has not observed a successful authentication attempt.

That distinction is important. There is currently no evidence from the research that the campaign resulted in successful AWS root account compromises.

But the activity still deserves attention.

Repeated failed attempts against privileged accounts can represent reconnaissance, credential testing or preparation for future operations. In modern cloud environments, even unsuccessful attacks can reveal important weaknesses in monitoring and incident-response processes.

The key question for security teams is not simply whether an attacker got in.

It is also: Would we know if they tried?

Identity Security Is Becoming a Front-Line Cloud Defense

The campaign arrives at a time when cloud identity has become central to enterprise security.

Traditional perimeter security assumed that protecting the network boundary was enough to keep attackers away from critical systems. Cloud computing changed that model. Today, identities, credentials, access policies and authentication mechanisms often sit directly between attackers and valuable infrastructure.

AWS recommends using temporary credentials and roles where possible rather than relying on long-term credentials. For human users, federation and centralized identity management can reduce the dependence on permanently assigned credentials. AWS also recommends least-privilege access and regular reviews of identities and permissions.

For organizations looking to strengthen their broader cybersecurity posture, this is an important lesson: protecting the cloud increasingly means protecting the identity layer first.

Why MFA Alone Is Not the Full Answer

Multi-factor authentication is a critical control, but it should not be treated as a complete strategy.

Datadog’s researchers specifically recommend reducing organizational dependence on persistent root credentials rather than relying on MFA alone.

For environments using AWS Organizations, centralized root access can allow organizations to reduce or remove long-term root credentials from member accounts while privileged tasks are performed through centrally authorized, short-lived sessions. Service Control Policies can also help restrict direct root activity in member accounts.

However, organizations should understand an important limitation: controls designed for member accounts do not automatically solve the security challenge of the AWS Organizations management account.

That root account requires separate and particularly strong protection.

AWS recommends monitoring root-user activity and safeguarding the credentials and recovery mechanisms associated with those accounts.

10 Actions Security Teams Should Take Now

Organizations do not need to wait for evidence of a compromise before reviewing their AWS root account security.

1. Review all root account activity

Treat every AWS root sign-in as security-relevant. Review recent authentication activity and establish alerts for unexpected root account access.

2. Enable and verify root MFA

Ensure MFA is properly configured for every applicable AWS root account. AWS recommends MFA for root users across all account types.

3. Prefer phishing-resistant authentication

Where possible, use passkeys or hardware security keys rather than relying exclusively on weaker authentication methods. AWS specifically recommends phishing-resistant MFA technologies where available.

4. Stop using the root account for daily work

Administrators should use appropriately configured identities, roles and temporary credentials for routine operations rather than logging in as root.

5. Remove unnecessary root credentials from member accounts

Organizations using AWS Organizations should evaluate centralized root access and determine whether persistent root credentials can be removed from member accounts.

6. Alert on failed root authentication attempts

Repeated ConsoleLogin failures should be investigated, particularly when they show unusual patterns, repeated attempts or suspicious infrastructure.

7. Monitor CloudTrail for root activity

Security teams should collect and analyze root sign-ins, root API activity, credential changes and privileged sessions. AWS recommends monitoring and alerting on root-user activity.

8. Eliminate root access keys

AWS strongly recommends against creating access keys for the root user because of the extensive privileges attached to the account.

9. Secure account recovery mechanisms

The email addresses, telephone numbers and MFA recovery processes connected to highly privileged cloud accounts deserve the same protection as the credentials themselves. AWS specifically recommends protecting and controlling access to root account recovery mechanisms.

10. Test your incident-response process

Security teams should know exactly what to do if suspicious root account activity appears. This includes validating alerting, defining escalation paths, preserving logs and preparing procedures for credential recovery or suspected account takeover.

Regular cybersecurity training and awareness can also help administrators and security teams recognize credential threats before they develop into larger incidents.

What This Means for Organizations in the Middle East and Africa

The campaign does not appear to target the MEA region specifically. Datadog found no clear geographic or industry victim pattern, so there is no evidence to suggest that organizations in the Middle East or Africa were uniquely targeted.

Still, the lesson is highly relevant to the region.

Governments, financial institutions, telecom providers, energy companies and rapidly growing technology businesses across MEA continue to expand their cloud environments. As organizations move more critical operations into public cloud platforms, the security of privileged identities becomes a strategic issue rather than simply an administrative one.

A root account is a global attack surface.

Whether an organization operates from Abu Dhabi, Riyadh, Nairobi, Johannesburg, London or Singapore, attackers can test exposed identity infrastructure from anywhere in the world.

The Bigger Picture: Attackers Are Testing the Doors

The Datadog research does not describe a confirmed compromise.

But it does reveal something equally important: attackers are actively testing the doors of some of the most privileged accounts in cloud environments.

More than 150 organizations were targeted. The victims were spread across countries and industries. The campaign used distributed proxy infrastructure. And although no successful authentication was observed, the attackers continued testing AWS root credentials for weeks.

That should be enough to prompt a review.

For cloud security leaders, the message is straightforward: the root account should be rare, heavily protected and constantly monitored not simply protected by a password and forgotten until an emergency.

Conclusion

The newly disclosed AWS root password-spraying campaign is a reminder that attackers continue to pursue privileged cloud identities even when strong security controls make those accounts difficult to compromise.

So far, Datadog has not observed a successful authentication attempt. That is the good news.

The warning, however, is clear.

Organizations should use this moment to review root account exposure, strengthen MFA, eliminate unnecessary long-term credentials, centralize privileged access where possible and ensure suspicious authentication activity is detected quickly.

In cloud security, attackers do not always need to break down the door.

Sometimes, they simply keep trying the handle.

Source: Datadog Security Labs research on the AWS root user password-spraying campaign.

Subscribe

- Never miss a story with notifications

- Gain full access to our premium content

- Browse free from up to 5 devices at once

Latest stories

spot_imgspot_imgspot_imgspot_img