ATC A.I CyberSecurity Scoring
ATC
Company Information
Website:https://aws.amazon.com/training/
Employees number:None
Number of followers:1,449,692
NAICS:5415
Industry Type:IT Services and IT Consulting
Homepage:amazon.com
ATC Risk Score (AI oriented)
Between 750 and 799
ATCIT Services and IT Consulting
Updated:
12/03/2026
12/03/2026
770/1000
Fair
Baa
ATC Global Score (TPRM)
xxxx
ATCIT Services and IT Consulting
Score locked

ATCFair
Current Score
770Baa (FAIR)
01000
1 incidents
-41 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
772
MAY 2026
771
APRIL 2026
771
MARCH 2026
770
FEBRUARY 2026
769
JANUARY 2026
769
DECEMBER 2025
768
NOVEMBER 2025
808
Breach
28 Nov 2025 • ATC
Amazon and AWS: 8-Minute Access: AI Accelerates Breach of AWS Environment
AI-Powered Attack Breaches AWS Environment in Under 10 Minutes
767
CRITICAL-41
AMAAWS1770152164
AI-Powered Attack Breaches AWS Environment in Under 10 Minutes
On November 28, 2025, a threat actor exploited exposed credentials in public Amazon S3 buckets to gain initial access to an AWS environment, escalating privileges to administrative control in just eight minutes. The attack, analyzed by Sysdig’s Threat Research Team (TRT), highlights the growing role of AI and large language models (LLMs) in accelerating cyber intrusions.
The attacker leveraged Lambda function code injection, repeatedly modifying an existing function (EC2-init) to target a user ("frick") with admin privileges. Once inside, they used AI-assisted techniques to automate reconnaissance, generate malicious code, and execute real-time decisions, significantly reducing the time defenders had to detect and respond.
Key tactics included:
- Programmatic interaction with AWS Marketplace APIs to access AI models (e.g., Claude, DeepSeek R1, Meta’s Llama 4 Scout) on the victim’s behalf.
- Cross-region inference profiles to distribute model invocations, complicating detection.
- Lateral movement across 19 AWS principals, including attempts to assume cross-account roles by enumerating account IDs some of which did not belong to the target organization.
- Provisioning GPU instances on EC2 for potential AI model development or resource abuse.
- Exfiltration of cloud data and abuse of Amazon Bedrock, an AI app-dev environment.
The attack’s speed and efficiency were attributed to AI-driven automation, with the threat actor writing code in Serbian and demonstrating advanced scripting techniques, including exception handling. Researchers noted hallucinated elements in the attacker’s scripts, further suggesting LLM assistance.
The initial breach stemmed from a basic security lapse: valid credentials left exposed in public S3 buckets, some named using common AI tool conventions. Experts emphasized that such oversights like relying on long-term IAM user credentials instead of temporary roles remain a persistent risk in cloud environments.
The incident underscores how AI is reshaping cyber threats, enabling attackers to execute complex operations with unprecedented speed and precision. As offensive AI tools improve, defenders face shrinking response windows, making runtime detection and least-privilege enforcement critical.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
OCTOBER 2025
808
SEPTEMBER 2025
808
AUGUST 2025
808
JULY 2025
808
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for ATC ??
What was ATC's A.I Rankiteo Cyber Score in May 2026 ??
What was ATC's A.I Rankiteo Cyber Score in April 2026 ??
What was ATC's A.I Rankiteo Cyber Score in March 2026 ??
What was ATC's A.I Rankiteo Cyber Score in February 2026 ??
What was ATC's A.I Rankiteo Cyber Score in January 2026 ??
What was ATC's A.I Rankiteo Cyber Score in December 2025 ??
What was ATC's A.I Rankiteo Cyber Score in November 2025 ??
What was ATC's A.I Rankiteo Cyber Score in October 2025 ??
What was ATC's A.I Rankiteo Cyber Score in September 2025 ??
What was ATC's A.I Rankiteo Cyber Score in August 2025 ??
What was ATC's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on ATC's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with ATC ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view ATC's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?