My s3 account was hacked and they deleted all the data and left a note

0

My s3 account was hacked and they deleted all the data and left a note, they want me to pay, how can I get files :(

To recover your lost files and avoid leaking it: In case of ignoring this message, all personal data will be published publicly open to everyone as well as traded on the Darknet. We will be the ones to mass mail all your clients with all links to where their personal data is open and traded.

Send us 0.3 Bitcoin (BTC) to our Bitcoin addresses Price is not standard, depend on your data.

Contact us by email to confirm awsrecovery@repairman.com

asked 8 months ago267 views
2 Answers
1

Hello.

Did you perform versioning settings or backup settings with AWS Backup on your S3 bucket?
If these settings are not made and objects in the S3 bucket are deleted, it will be impossible to restore them unless the original data is managed on a local PC.
https://docs.aws.amazon.com/AmazonS3/latest/userguide/Versioning.html
https://docs.aws.amazon.com/aws-backup/latest/devguide/s3-backups.html

Also, never comply with the attacker's demands.
Your data will not be recovered even if you comply with the attacker's requests.

Also, identify IAM users used for unauthorized access from CloudTrail event history and delete them immediately.
https://repost.aws/knowledge-center/potential-account-compromise

profile picture
EXPERT
answered 8 months ago
profile pictureAWS
EXPERT
reviewed 8 months ago
1

First and foremost, don't listen to bad actors as data wouldn't be recovered regardless. Start following the best practices to secure your AWS account and resources.

As mentioned above, there are some s3 bucket best practices, one must follow and couple of them I'd like to highlight here:

  • Enable Versioning and have backups
  • Bucket policy must be strict enough, even if someone gets into account, he/she should not have delete access(some sort of DenyAllExcept)

Reference for making your account and resources more secure:

profile pictureAWS
EXPERT
answered 8 months ago
profile pictureAWS
EXPERT
reviewed 8 months ago

You are not logged in. Log in to post an answer.

A good answer clearly answers the question and provides constructive feedback and encourages professional growth in the question asker.

Guidelines for Answering Questions