Ask HN: Our AWS account got compromised after their outage

https://news.ycombinator.com/rss Hits: 21
Summary

Could there be any link between the two events?Here is what happened:Some 600 instances were spawned within 3 hours before AWS flagged it off and sent us a health event. There were numerous domains verified and we could see SES quota increase request was made.We are still investigating the vulnerability at our end. our initial suspect list has 2 suspects. api key or console access where MFA wasn’t enabled.

First seen: 2025-10-21 17:10

Last seen: 2025-10-22 17:25