Skip to content

이메일이 왔는데 어떻게 해야하나요?

0

아래와 같은 메일이 왔는데 어떻게 해야하나요? 무단사용하지 않았으니 해결해주실수 있나요?

日付: 2024年12月13日(金) 3:53 件名: RE:[CASE 173382692100847] [Action Required] Unexpected Activity Detected on your AWS Account [AWS Account: 582321609766]

Hello,

We recently contacted you because we observed anomalous activity in your AWS account that indicated that one or more of your AWS access keys, along with the corresponding secret key, may have been inappropriately accessed by a third party. In our last correspondence, we incorrectly stated “To protect your account from excessive charges, we have temporarily limited your ability to use some AWS services. [...] If the unauthorized usage is not stopped we may suspend your AWS account.” We apologize that this was incorrectly added by our automated process to this support case: your account has not been limited and is not at risk of suspension as part of this specific case.

We still strongly recommend that you immediately follow the previously communicated instructions to protect your account.

Date: 2024年12月10日(火) 19:34 Subject: [Action Required] Unexpected Activity Detected on your AWS Account [AWS Account: 582321609766]

Hello,

As part of our standard monitoring of AWS systems, we observed anomalous activity in your AWS account that indicated that your AWS access keys, along with the corresponding secret key, may have been inappropriately accessed by a third party. Unauthorized users with an AWS access key could take mutating actions on your AWS resources or read your data. We strongly recommend that you immediately follow the instructions below to protect your account. AWS systems continue to operate as designed.

A list of your affected resource(s) can be found in the 'Affected resources' tab of your AWS Health Dashboard in the format 'Access KeyId | IAM Principal ARN'.

To prevent restricted access, please work with your TAM/Account Manager and/or use the instructions in the following sections. Refer to the user guide [1] for detailed instructions.

As a security best practice, we recommend that you enable multi-factor authentication (MFA) [2].

Step 1: If your application uses the exposed access key, you must replace the key. We recommend you create a second key, and then modify your application to use this new key to replace the exposed access key.

Next, disable (do not delete) the exposed key by clicking on the “Make inactive” option in the console. If there are any problems with your application, you can reactivate the exposed key. When your application is fully functional using the new key, delete the exposed access key(s) identified above.

To delete IAM user keys, go to your AWS Management Console - Users [3]. To delete Root user keys, go to your AWS Management Console - Security Credential [4].

Please note, only rotating and deleting the exposed key may not be sufficient to protect your account, continue to Step 2.

Step 2: Check your CloudTrail log for unwanted activity.

Check your account for any unwanted activity, such as creation of unapproved IAM users and/or associated passwords (login profile), access keys, policies, roles or temporary security credentials by checking your CloudTrail log, and immediately delete them.

To delete IAM users, go to your AWS Management Console - Users [5]. To delete policies, go to your AWS Management Console - Policies [6]. To delete roles, go to your AWS Management Console - Roles [7].

Deleting IAM users may impact production workloads and should be done carefully.

Step 3: Review your AWS account for any unwanted AWS usage. Check your account for any unwanted usage, such as S3 reads, S3 writes, S3 bucket creates and/or S3 bucket deletes, EC2 instances, Lambda functions, or EC2 Spot bids by logging into your AWS Management Console and reviewing each service page. You can also do this by checking the "Bills" page in the Billing console [8].

Unwanted usage can occur in any region and your console only displays one region at a time. To switch regions, use the drop-down menu in the top-right corner of the console.

Step 4: You must either respond to your TAM/Account Manager or update your existing Support Case [9] to confirm completion of steps 1-3.

If you need help completing the steps to secure your account, please contact your TAM/Account Manager or request a phone call or chat session through the Support Case for immediate assistance. Alternatively, if you believe that your account is secured and there is no inappropriate access or usage, please contact us immediately via the Support Case to confirm this in writing.

Thank you for your immediate attention to this matter.

[1] https://aws.amazon.com/premiumsupport/knowledge-center/potential-account-compromise/ [2] https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_mfa_enable.html [3] https://console.aws.amazon.com/iam/home#users [4] https://console.aws.amazon.com/iam/home#security_credential [5] https://console.aws.amazon.com/iamv2/home#/users [6] https://console.aws.amazon.com/iam/home#/policies [7] https://console.aws.amazon.com/iam/home#/roles [8] https://console.aws.amazon.com/billing/home#/bill [9] https://console.aws.amazon.com/support/home?#/

Sincerely, Amazon Web Services

Amazon Web Services, Inc. is a subsidiary of Amazon.com, Inc. Amazon.com is a registered trademark of Amazon.com, Inc. This message was produced and distributed by Amazon Web Services Inc.,


Reference: https://health.aws.amazon.com/health/home#/account/event-log?Event%20ARN=arn:aws:health:global::event/IAM/AWS_IAM_CUSTOMER_ENGAGEMENT/AWS_IAM_CUSTOMER_ENGAGEMENT_A1743_A290E507F31&eventID=arn:aws:health:global::event/IAM/AWS_IAM_CUSTOMER_ENGAGEMENT/AWS_IAM_CUSTOMER_ENGAGEMENT_A1743_A290E507F31&eventTab=details&layout=vertical

Date: 2024年12月11日(水) 19:35 Subject: RE:[CASE 173382692100847] [Action Required] Unexpected Activity Detected on your AWS Account [AWS Account: 582321609766]

Dear AWS Customer,

We are following up with you, as your AWS Account may still be compromised. Please review the previous notice we have sent and take immediate action to secure your account. If you believe that your account is secured and there is no unauthorized access or usage, please contact us immediately by responding to this Support case.

This account compromise poses a security risk to your account (including other account users), and could lead to excessive charges from unauthorized activity. To protect your account from excessive charges, we have temporarily limited your ability to use some AWS services. To remove the limits, please follow the instructions provided in our initial notice.

If the unauthorized usage is not stopped we may suspend your AWS account. To further protect your account from excessive charges, we may terminate any suspected unauthorized resources on your account.

If you have any questions, please contact us by responding through this Support case.

Dear AWS Customer,

We are following up with you, as your AWS Account may still be compromised. Please review the previous notice we have sent and take immediate action to secure your account. If you believe that your account is secured and there is no unauthorized access or usage, please contact us immediately by responding to this Support case.

This account compromise poses a security risk to your account (including other account users), and could lead to excessive charges from unauthorized activity. To protect your account from excessive charges, we have temporarily limited your ability to use some AWS services. To remove the limits, please follow the instructions provided in our initial notice.

If the unauthorized usage is not stopped we may suspend your AWS account. To further protect your account from excessive charges, we may terminate any suspected unauthorized resources on your account.

If you have any questions, please contact us by responding through this Support case.

To share your experience or contact us again about this case, please return to the AWS Support Center using the following URL: https://console.aws.amazon.com/support/home#/case/?displayId=173382692100847&language=en

Note, this e-mail was sent from an address that cannot accept incoming e-mails. To respond to this case, please follow the link above to respond from your AWS Support Center.

===============================================================

Don’t miss messages from AWS Support when you need help! Update your contact information: https://console.aws.amazon.com/billing/home#/account

If you receive an error message when visiting the contact information page, visit: https://repost.aws/knowledge-center/iam-billing-access/

AWS Support: https://repost.aws/knowledge-center/

AWS Documentation: https://docs.aws.amazon.com/

AWS Cost Management: https://aws.amazon.com/aws-cost-management/

AWS Training: http://aws.amazon.com/training/

AWS Managed Services: https://aws.amazon.com/managed-services/

asked 2 years ago330 views

1 Answer
0

이 상황에 대해 다음과 같은 조치를 취하는 것이 좋습니다:

  1. AWS에서 보낸 이메일을 주의 깊게 검토하세요. 계정에 비정상적인 활동이 감지되었다는 내용입니다.

  2. AWS 액세스 키와 비밀 키가 제3자에 의해 부적절하게 접근되었을 가능성이 있으므로, 즉시 조치를 취해야 합니다.

  3. 다음 단계를 따라 계정을 보호하세요:

    • 노출된 액세스 키를 새 키로 교체하세요.
    • CloudTrail 로그를 확인하여 원치 않는 활동이 있는지 검토하세요.
    • 승인되지 않은 IAM 사용자, 정책, 역할 등이 생성되었는지 확인하고 삭제하세요.
    • 각 AWS 서비스 페이지와 청구 콘솔을 검토하여 원치 않는 사용이 있는지 확인하세요.
  4. 다중 인증(MFA)을 활성화하여 계정 보안을 강화하세요.

  5. 이러한 조치를 완료한 후, AWS 지원 케이스를 통해 조치 완료를 확인해주세요.

  6. 계정이 안전하다고 확신한다면, 지원 케이스를 통해 즉시 AWS에 연락하여 서면으로 확인해주세요.

  7. 도움이 필요하면 AWS 지원팀에 연락하여 즉각적인 지원을 요청하세요.

무단 사용을 하지 않았다고 하더라도, 이러한 보안 조치를 취하는 것이 중요합니다. AWS는 계정 보안을 위해 이러한 알림을 보내며, 조치를 취하지 않으면 일부 서비스 사용이 제한되거나 계정이 일시 중지될 수 있습니다.

Sources
Email from AWS about an abuse of its usage policy | AWS re:Post
Keep receiving mails that my account is compromised | AWS re:Post
AWS account email has been changed | AWS re:Post

answered 2 years ago

You are not logged in. Log in to post an answer.

A good answer clearly answers the question and provides constructive feedback and encourages professional growth in the question asker.