[CASE 8758971071] Notification: Irregular activity in AWS account 888854011343

From: no-reply-aws@amazon.com
Domain: IP info amazon.com
MX-server: IP info a13-10.smtp-out.amazonses.com
Size: 7540 Bytes
Create: 2021-08-21
Sent: 2021-08-21 10:35
Update: 2021-08-21
Score: 1
Safe: Yes

Hello, We detected an abnormal pattern in your AWS account that matches unauthorized activity. In accordance with the AWS Customer Agreement and/or other agreements with us governing your use of our service, and to protect your account from excessive charges, we may terminate any suspected unauthorized resources on your account and limit your ability to use the AWS service. However, please note that this does not make your account secure. The following steps are required to secure your AWS account. If you don't take the steps within five days (in accordance with the AWS Customer Agreement), we may suspend your account. Let us know after you complete the steps, and please make sure to leave the support case open. STEPS TO SECURE YOUR ACCOUNT: * Step 1: Change your AWS account root user password. See the following for instructions: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_access-keys_retrieve.html#reset-root-password * Step 2: Check your CloudTrail log in each region for unsanctioned activity (such as creation of unauthorized IAM users, AWS access keys, policies, roles, or temporary security credentials) and delete them. See the following for more information: https://docs.aws.amazon.com/awscloudtrail/latest/userguide/view-cloudtrail-events.html https://aws.amazon.com/cloudtrail/pricing/ To delete IAM user keys go to your AWS Management Console here: https://console.aws.amazon.com/iam/home#users To delete Root User Keys go here: https://console.aws.amazon.com/iam/home#security_credential If your application uses any exposed or compromised access key, you need to replace the key. To replace the key, first create a second key (at that point both keys will be active) and then modify your application to use the new key. Then disable (but do not delete) the exposed key by clicking on the “Make inactive” option in the console. If there are any problems with your application, you can reactivate the exposed key. When your application is fully functional using the new key, please delete the exposed key. See the following for additional information: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_access-keys.html#Using_RotateAccessKey https://aws.amazon.com/premiumsupport/knowledge-center/delete-access-key/ To delete unauthorized IAM Users, go here: https://console.aws.amazon.com/iam/home#users To delete unauthorized roles go here: https://console.aws.amazon.com/iam/home#/roles To revoke temporary credentials, see the following: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_control-access_disable-perms.html#denying-access-to-credentials-by-issue-time Temporary credentials can also be revoked by deleting the IAM User. NOTE: Deleting IAM users may impact production workloads and should be done with care. You cannot revoke temporary credentials obtained via the root user, see the following for more information: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_control-access_disable-perms.html#denying-access-to-credentials-creator Please take steps to prevent any new credentials from being publicly exposed. See Best Practices of Managing your Access Keys here: http://docs.aws.amazon.com/general/latest/gr/aws-access-keys-best-practices.html * Step 3: Do the following to check for unauthorized AWS usage: - Check your CloudTrail logs - Check your “Bills” page: https://console.aws.amazon.com/billing/home#/bill - Check Cost Explorer: https://docs.aws.amazon.com/awsaccountbilling/latest/aboutv2/ce-what-is.html Some common usage types to check for are EC2 instances, EC2 Spot bids, Lambda functions, AMIs, EBS volumes, EBS snapshots, Lightsail instances, and Sagemaker notebook instances. Here’s some helpful documentation on deleting resources associated with those services: EC2 instances: https://aws.amazon.com/premiumsupport/knowledge-center/delete-terminate-ec2/ EC2 Spot bids: https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/spot-requests.html#terminating-a-spot-instance Lambda functions: https://docs.aws.amazon.com/lambda/latest/dg/API_DeleteFunction.html AMIs: https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/deregister-ami.html EBS volumes: https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ebs-deleting-volume.html EBS snapshots: https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ebs-deleting-snapshot.html#ebs-delete-snapshot Lightsail instances: https://lightsail.aws.amazon.com/ls/docs/en_us/articles/delete-an-amazon-lightsail-instance Sagemaker notebook instances: https://docs.aws.amazon.com/sagemaker/latest/dg/ex1-cleanup.html For information on how to delete a resource associated with other AWS services, please see our documentation for the specific service on the following page: https://docs.aws.amazon.com/index.html#lang/en_us Keep in mind that unauthorized usage can occur in any region and that your console may show you only one region at a time. To switch between regions, you can use the dropdown in the top-right corner of the console screen. Also, please make sure that no termination protection or any other back-up restoration system such as ELB or AutoScaling groups is enabled on the resources you want to delete. More information can be found here: https://aws.amazon.com/premiumsupport/knowledge-center/ec2-instance-relaunched-after-termination/ https://aws.amazon.com/premiumsupport/knowledge-center/source-ec2-instances/ We recommend that you enable amazon GuardDuty: Amazon GuardDuty is an AWS threat detection service that helps you continuously monitor and protect your AWS accounts and workloads. Enabling Amazon GuardDuty on your accounts gives you further visibility into malicious or unauthorized activity, alerting you to take action in order to reduce the risk of harm. To learn more, visit: https://aws.amazon.com/guardduty For additional information on re-securing your account see the following page: https://aws.amazon.com/premiumsupport/knowledge-center/potential-account-compromise If you have any questions or require guidance with this process, please notify us by replying to this case in your Support Center. If you prefer to speak directly with an agent by phone, please find this case in your Support Center (https://console.aws.amazon.com/support/home), then click the "Phone" button and we will be in touch as soon as possible. We value your feedback. Please share your experience by rating this correspondence using the AWS Support Center link at the end of this correspondence. Each correspondence can also be rated by selecting the stars in top right corner of each correspondence within the AWS Support Center. Best regards, Ishi N. Amazon Web Services =============================================================== To share your experience or contact us again about this case, please return to the AWS Support Center using the following URL: https://console.aws.amazon.com/support/home#/case/?displayId=8758971071&language=en Note, this e-mail was sent from an address that cannot accept incoming e-mails. To respond to this case, please follow the link above to respond from your AWS Support Center. =============================================================== AWS Support: https://aws.amazon.com/premiumsupport/knowledge-center/ AWS Documentation: https://docs.aws.amazon.com/ AWS Cost Management: https://aws.amazon.com/aws-cost-management/ AWS Training: http://aws.amazon.com/training/ AWS Managed Services: https://aws.amazon.com/managed-services/