← Back to News

AWS CIRT Flags Cloud Data Theft Patterns

2026-07-01 · aws-security

AWS Security published the June 2026 update to the Threat Technique Catalog for AWS, based on patterns observed by the AWS Customer Incident Response Team. The update focuses on container security, organization-level trust abuse, compute hijacking, and refreshed guidance for S3 object collection.


What Happened

AWS added five new catalog entries and updated three existing entries, including EKS workload modification, public-facing EKS exploitation, AssumeRoot abuse in AWS Organizations, EKS compute hijacking, and malicious organization invitations. It also refreshed S3 Object Collection guidance to cover additional bulk data staging patterns and newer S3 security features.

The Cost of Data Loss

These techniques show how attackers can use legitimate cloud functionality to alter workloads, gain root-level organizational access, consume compute, and stage object data. If online backups, logs, or recovery artifacts live inside the same compromised control plane, responders may lose both production data and the evidence needed to rebuild safely.

How Cold Storage Prevents This

Offline, immutable copies of critical datasets, configuration exports, recovery runbooks, and key custody records reduce the blast radius when cloud accounts are altered or locked down. Cold storage does not stop the intrusion, but it preserves a trusted recovery point outside the attacker-controlled environment.

Read Original Post →