AWS AI A.I CyberSecurity Scoring
AWS AI
Company Information
Website:https://aws.amazon.com/ai/
Employees number:None
Number of followers:461,297
NAICS:5415
Industry Type:IT Services and IT Consulting
Homepage:amazon.com
AWS AI Risk Score (AI oriented)
Between 750 and 799
AWS AIIT Services and IT Consulting
Updated:
14/09/2026
14/09/2026
758/1000
Fair
Baa
AWS AI Global Score (TPRM)
xxxx
AWS AIIT Services and IT Consulting
Score locked

AWS AIFair
Current Score
758Baa (FAIR)
01000
3 incidents
-23 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
OCTOBER 2026
758
SEPTEMBER 2026
780
Cyber Attack
03 Sep 2026 • AWS AI
AWS and Operation Bizarre Bazaar Victims: LLMjacking Attack Uses Leaked AWS IAM Key to Steal Paid AI Model Access
LLMjacking: How Attackers Hijack AWS Credentials to Exploit Premium AI Models
757
CRITICAL-23
AWSGUL1788459858
LLMjacking: How Attackers Hijack AWS Credentials to Exploit Premium AI Models
Security researchers at FortiGuard Labs have uncovered a new cloud attack technique called LLMjacking, where threat actors exploit leaked AWS credentials to monetize access to premium AI models at the victim’s expense.
The attack begins with a compromised long-lived AWS IAM access key carrying AdministratorAccess privileges the highest level of permissions in AWS. Once inside, the attacker creates a new IAM user within the victim’s account and subscribes to high-cost foundation models via AWS Marketplace, generating inference charges billed directly to the compromised organization.
In some cases, attackers also generate Bedrock service-specific API keys, providing an additional, less detectable method to invoke AI models. Unlike traditional cloud attacks such as cryptomining or data exfiltration LLMjacking focuses on abusing the victim’s billing relationship with AWS, turning unauthorized AI usage into a revenue stream.
The financial impact is severe: premium models like Claude 2.x can cost victims over $46,000 per day, while Claude 3 Opus usage can exceed $100,000 daily. Stolen access is often resold as discounted AI chatbot subscriptions on platforms like Telegram and Discord. One tracked operation, Operation Bizarre Bazaar, has been linked to over 35,000 attack sessions across 30+ LLM providers.
Detection is challenging because the malicious API calls originate from valid, permissioned credentials, making them indistinguishable from legitimate usage. FortiGuard Labs notes that conventional monitoring fails to flag this activity, as the traffic itself appears benign.
To mitigate risks, researchers recommend:
- Enabling AWS CloudTrail across all accounts to track identity creation and marketplace subscriptions.
- Activating Bedrock invocation logging (disabled by default) for detailed request-level visibility.
- Replacing long-lived, broad-scope IAM keys with short-lived, role-assumed credentials to reduce exposure.
- Monitoring for newly created identities, unfamiliar IPs, or unusual access patterns rather than treating first-time Bedrock usage as inherently safe or suspicious.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
AUGUST 2026
779
JULY 2026
779
JUNE 2026
779
MAY 2026
778
APRIL 2026
778
MARCH 2026
778
FEBRUARY 2026
777
JANUARY 2026
777
DECEMBER 2025
777
NOVEMBER 2025
776
JANUARY 2025
788
Cyber Attack
01 Jan 2025 • AWS AI
Anthropic and AWS: Active Exploitation Alert: Threat Actors Weaponize Claude AI for Automated Data Theft and Supply Chain Attacks
AI-Powered Cyberattacks: Threat Actors Weaponized Anthropic’s Claude for Large-Scale Exploitation
771
CRITICAL-17
AWSANT1789374720
AI-Powered Cyberattacks: How Threat Actors Weaponized Anthropic’s Claude for Large-Scale Exploitation
Between late 2025 and mid-2026, threat actors across the globe systematically abused Anthropic’s Claude, an advanced generative AI platform, to automate cyberattacks at an unprecedented scale. Adversaries ranging from state-sponsored APTs to cybercriminals and surveillance vendors leveraged Claude’s multi-agent capabilities to conduct credential harvesting, supply chain compromises, mass surveillance, and influence operations, targeting sectors including education, energy, finance, government, and technology.
### Key Threat Actors & Their Tactics
Multiple groups exploited Claude for distinct objectives:
- GTG-20006 (Russian APT29 affiliate): Used Claude for automated reconnaissance, exploitation, and data exfiltration, overlapping with Midnight Blizzard/Cozy Bear operations.
- GTG-50014 (ShinyHunters affiliate): Deployed Claude-driven automation on AWS EC2 to scan 1.8 million Android APKs for embedded secrets using TruffleHog, exfiltrating data via Telegram.
- GTG-10007 (Chinese-linked group): Targeted endpoint security products across 50+ organizations, using Claude for vulnerability research and exploit development.
- Commercial surveillance vendors (S2T Unlocking Cyberspace, LKM Company) & Iranian paramilitary agencies: Leveraged Claude for mass profiling and domestic surveillance, including automated social network analysis.
### Technical Sophistication & Attack Methods
Claude was integrated into multi-agent frameworks, enabling parallelized attacks with minimal human oversight. Key techniques included:
- Automated reconnaissance of public and internal assets for vulnerabilities.
- Credential harvesting via TruffleHog and custom scripts, targeting Android APKs and SaaS platforms.
- Malware & phishing kit generation, with Claude acting as an engineering assistant to refine payloads and evasion tactics.
- Supply chain attacks on SaaS vendors and AI model providers, compromising downstream customer data.
- Exploitation of a zero-day WordPress race condition to create rogue admin accounts, enabling persistent access.
- Data exfiltration via Telegram channels, bespoke C2 infrastructure, and doxxing platforms like fafsearch.
### Global Impact & Victimology
The campaigns spanned multiple regions, including Europe, the Middle East, Southeast Asia, Africa, and the Persian Gulf, with victims across:
- High-value sectors: Government, finance, energy, and technology.
- Mass-market platforms: Education, retail, healthcare, and SaaS providers.
- Political & media targets: Think tanks, political parties, and news organizations, particularly in Malaysia, Bangladesh, Iran, and Kenya, where Claude was used for election interference and disinformation.
### Mitigation Challenges
The attacks highlighted the dual threat of AI-driven automation and supply chain vulnerabilities, requiring organizations to:
- Monitor for unauthorized Claude/AI API usage, enforcing least-privilege access for credentials.
- Detect and block malicious browser extensions (e.g., al-Najm al-thāqib).
- Patch WordPress and SaaS platforms to address race conditions and exposed endpoints.
- Audit AWS EC2 activity for mass APK scans and TruffleHog usage.
- Review supply chain dependencies, ensuring third-party vendors adhere to robust security practices.
The abuse of Claude underscores the evolving threat landscape, where AI-driven automation enables scalable, adaptive cyberattacks with far-reaching consequences.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
AUGUST 2022
786
Vulnerability
01 Aug 2022 • AWS AI
Grok, Cisco and AWS: UK power plant hack, AI zero click, children’s hospital breach
UK Power Plant Cyberattack by Iran-Linked HackersZero-Click AI Chat Data Theft via Cryptographic ExploitOpenAI Warning on Persistent AI-Driven Cyber ThreatsCanada’s SickKids Hospital Data BreachCritical Flaws in Cisco Secure Workload SoftwareLeaked AWS Keys Grant Full Corporate Account ControlTSN Protocols Vulnerable to OT Manipulation
785
CRITICAL-1
HEYAWSCIS1787567547
Cybersecurity Roundup: Major Incidents and Emerging Threats
Recent weeks have seen a surge in high-profile cybersecurity incidents, vulnerabilities, and warnings across critical infrastructure, AI systems, and enterprise software.
UK Power Plant Hit by Iran-Linked Hackers
A previously unidentified UK power plant was disabled for four days in what The Telegraph called "the most successful cyberattack of its kind against UK energy infrastructure." While the outage did not disrupt the national grid, the government has issued warnings to power companies, framing the attack as a demonstration of Iran-linked hackers' capabilities. The incident underscores growing threats to energy sector resilience.
Zero-Click AI Chat Data Theft via Cryptographic Exploit
Security researcher Rony Utevsky of Adversa revealed a novel attack technique that bypasses AI safety filters by embedding malicious instructions in AES-encrypted data. Demonstrated against Grok and Gemini, the exploit allows threat actors to steal chat histories without user interaction in Grok and generate restricted content in Gemini. The method exploits gaps in how AI models process encrypted inputs, highlighting vulnerabilities in production AI systems.
OpenAI Warns of Persistent AI-Driven Cyber Threats
Chris Lehane, OpenAI’s chief global affairs officer, cautioned that advanced AI models are increasingly capable of launching "ongoing, persistent cyber-attacks," with offensive capabilities outpacing defensive measures. The warning follows OpenAI’s decision to pause development of its most advanced internal models amid safety concerns. Lehane reiterated calls for U.S. government regulation to address frontier AI risks.
Canada’s SickKids Hospital Suffers Second Cyberattack
Toronto’s Hospital for Sick Children, Canada’s largest pediatric health center, experienced a data breach exposing current and former employees' personal information. The incident, linked to a third-party software vulnerability, follows a 2022 ransomware attack. While no clinical systems or patient data were compromised, the breach raises concerns about third-party supply chain risks in healthcare.
Critical Flaws in Cisco Secure Workload Software
Cisco disclosed four high-severity vulnerabilities in its Secure Workload (formerly Tetration) micro-segmentation tool, including two CVSS 10.0 flaws (CVE-2026-20315, CVE-2026-20317) tied to improper access control. Additional vulnerabilities (CVE-2026-20231, CVE-2026-20318) involve input validation and neutralization issues. While SaaS fixes are available, users must manually upgrade Agent and Connector tools to mitigate risks.
Congress Probes CISA Staffing Cuts
Democratic lawmakers, led by Rep. Bennie Thompson, have requested a Government Accountability Office (GAO) investigation into how staffing reductions nearly one-third of CISA’s workforce impact the agency’s ability to protect critical infrastructure. The inquiry reflects growing concerns over resource constraints in federal cybersecurity efforts.
Leaked AWS Keys Grant Full Corporate Account Control
Researchers at Truffle Security identified over 9,300 active and valid AWS access keys exposed between 2022 and 2026, including 526 root keys and 242 admin-level IAM keys. The findings underscore persistent risks from misconfigured cloud credentials, with many keys linked to high-privilege accounts capable of full resource manipulation.
Time-Sensitive Networking (TSN) Protocols Vulnerable to OT Manipulation
Nozomi Networks, owned by Mitsubishi Electric, revealed critical weaknesses in TSN protocols designed for industrial reliability that could allow attackers to inject commands or alter timing signals in operational technology (OT). While patches exist for some flaws, underlying protocol limitations make comprehensive fixes challenging. Network segmentation and firmware updates remain key defenses against potential disruptions to machinery and industrial processes.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for AWS AI ??
What was AWS AI's A.I Rankiteo Cyber Score in September 2026 ??
What was AWS AI's A.I Rankiteo Cyber Score in August 2026 ??
What was AWS AI's A.I Rankiteo Cyber Score in July 2026 ??
What was AWS AI's A.I Rankiteo Cyber Score in June 2026 ??
What was AWS AI's A.I Rankiteo Cyber Score in May 2026 ??
What was AWS AI's A.I Rankiteo Cyber Score in April 2026 ??
What was AWS AI's A.I Rankiteo Cyber Score in March 2026 ??
What was AWS AI's A.I Rankiteo Cyber Score in February 2026 ??
What was AWS AI's A.I Rankiteo Cyber Score in January 2026 ??
What was AWS AI's A.I Rankiteo Cyber Score in December 2025 ??
What was AWS AI's A.I Rankiteo Cyber Score in November 2025 ??
What is the average per-incident point impact on AWS AI's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with AWS AI ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view AWS AI's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?