Incident
Published 2026-09-01
Verified 2026-09-19

Datadog: password-spraying against AWS root console at 150+ organisations

Datadog Security Research describes a password-spraying campaign against AWS root-user console logins at more than 150 organisations between 24 July and 23 August 2026. The median number of failed attempts per organisation was two; some saw as many as eight. The AWS root console requires the account email, so the campaign implies the operators had (or guessed) those addresses. This desk records failed attempts as reported; no successful authentications are stated in the Datadog write-up as loaded. Coverage on 1 September 2026 (Cyber Security News) likewise says researchers did not identify successful authentications. Organisations should review CloudTrail for unusual root ConsoleLogin failures and keep root use exceptional.

Product
AWS root user console
Exploited in Australia?
unknown
Patch to
Review CloudTrail root ConsoleLogin failures; minimise root use

Primary: Datadog Security Labs ยท Cyber Security News (1 Sep 2026)

tech cloud identity ai