One Person, 72 Hours, One Wrecked AWS Account: How AI Handed a Lone Criminal the Keys to a Global Enterprise

Incident-response firm Sygnia says a single attacker used AI to tear through a major cloud environment at a pace that would normally require a full criminal crew. The unnamed victim was extorted.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
Illustration: An empty, dimly lit server room at night
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • A single criminal broke into a large Amazon Web Services cloud environment in roughly 72 hours, according to incident-response firm Sygnia.
  • The attacker used AI tools to speed up reconnaissance (the process of scouting a target's systems) and build attack tools on the fly.
  • No single password or software flaw opened the door; the criminal chained together multiple smaller weaknesses across the victim's cloud setup.
  • The unnamed victim, described as a global enterprise, was financially extorted after the attacker demonstrated the ability to shut down critical services.
  • Sygnia published its findings in a research report this week, first covered by Dark Reading.

A single criminal just proved you don't need a gang to pull off an enterprise-scale cloud heist. You need AI and a weekend.

Cybersecurity and incident-response company Sygnia released research this week describing how one attacker broke into a large Amazon Web Services (AWS) environment, the cloud computing platform thousands of businesses use to store data and run software, and extorted an unnamed global company in approximately 72 hours.

How did the attacker get in?

The criminal got a foothold through an internet-facing application that exposed an AWS access key, a digital credential that grants commands over cloud resources. That key was fed into four separate automated workflows, meaning pre-written sequences of actions an AI tool could run without stopping for human input, to harvest credentials, build backdoors, exfiltrate data and locate new access points simultaneously. Every time a new set of credentials surfaced, the attacker ran them through the same four workflows again.

No single catastrophic flaw made this possible. Sygnia says the attacker threaded together weaknesses across application services, source-code repositories, CI/CD pipelines (the automated systems companies use to build and update software) and data stores. Individually, none of those gaps would have been enough. Together, they handed over the keys to the building.

What made this unusual was speed. Sygnia's researchers examined attacker-written scripts, the volume of cloud techniques used and the parallel timing of activity, then concluded that one person accomplished in three days what would typically take a team several weeks. AI-assisted workflows handled the scanning, adapted commands to fit what the attacker found and generated tools on the spot.

We covered how AWS credential theft via developer tooling works in our 3 July story on Amazon's AI coding assistant flaw; the method here is different, but the harvest-then-escalate logic is the same.

To pressure the victim into paying, the attacker performed reversible but painful disruptions: blocking access to S3 buckets (online storage containers), throttling computing services to zero capacity and purging message queues. The message was clear. Pay, or the next round is permanent.

Should you worry?

Sygnia vice president Avi Dayan told Dark Reading that if an AI tool can exfiltrate data in under a minute, a security team waiting on a human analyst to review an alert will always lose. He argued that security operations need automated, high-fidelity response playbooks just to match the attacker's pace.

Sygnia's recommended response: maintain visibility across every account and asset, tighten identity controls so stolen keys can't roam freely, automate detection and response, and have containment procedures written down before you need them. Delays in containment, the research notes, have a disproportionate impact when an attacker is moving this fast.

The beat observation worth flagging here is that the attacker didn't need a novel exploit or a zero-day. Chained misconfigurations plus AI tooling was enough. That's the part defenders should be losing sleep over, not the sophistication of any single technique.

© 2026 Threat Vectr