아래와 같은 메일이 왔는데 어떻게 해야하나요?
무단사용하지 않았으니 해결해주실수 있나요?
日付: 2024年12月13日(金) 3:53
件名: RE:[CASE 173382692100847] [Action Required] Unexpected Activity Detected on your AWS Account [AWS Account: 582321609766]
Hello,
We recently contacted you because we observed anomalous activity in your AWS account that indicated that one or more of your AWS access keys, along with the corresponding secret key, may have been inappropriately accessed by a third party. In our last correspondence, we incorrectly stated “To protect your account from excessive charges, we have temporarily limited your ability to use some AWS services. [...] If the unauthorized usage is not stopped we may suspend your AWS account.” We apologize that this was incorrectly added by our automated process to this support case: your account has not been limited and is not at risk of suspension as part of this specific case.
We still strongly recommend that you immediately follow the previously communicated instructions to protect your account.
Date: 2024年12月10日(火) 19:34
Subject: [Action Required] Unexpected Activity Detected on your AWS Account [AWS Account: 582321609766]
Hello,
As part of our standard monitoring of AWS systems, we observed anomalous activity in your AWS account that indicated that your AWS access keys, along with the corresponding secret key, may have been inappropriately accessed by a third party. Unauthorized users with an AWS access key could take mutating actions on your AWS resources or read your data. We strongly recommend that you immediately follow the instructions below to protect your account. AWS systems continue to operate as designed.
A list of your affected resource(s) can be found in the 'Affected resources' tab of your AWS Health Dashboard in the format 'Access KeyId | IAM Principal ARN'.
To prevent restricted access, please work with your TAM/Account Manager and/or use the instructions in the following sections. Refer to the user guide [1] for detailed instructions.
As a security best practice, we recommend that you enable multi-factor authentication (MFA) [2].
Step 1: If your application uses the exposed access key, you must replace the key. We recommend you create a second key, and then modify your application to use this new key to replace the exposed access key.
Next, disable (do not delete) the exposed key by clicking on the “Make inactive” option in the console. If there are any problems with your application, you can reactivate the exposed key. When your application is fully functional using the new key, delete the exposed access key(s) identified above.
To delete IAM user keys, go to your AWS Management Console - Users [3].
To delete Root user keys, go to your AWS Management Console - Security Credential [4].
Please note, only rotating and deleting the exposed key may not be sufficient to protect your account, continue to Step 2.
Step 2: Check your CloudTrail log for unwanted activity.
Check your account for any unwanted activity, such as creation of unapproved IAM users and/or associated passwords (login profile), access keys, policies, roles or temporary security credentials by checking your CloudTrail log, and immediately delete them.
To delete IAM users, go to your AWS Management Console - Users [5].
To delete policies, go to your AWS Management Console - Policies [6].
To delete roles, go to your AWS Management Console - Roles [7].
Deleting IAM users may impact production workloads and should be done carefully.
Step 3: Review your AWS account for any unwanted AWS usage.
Check your account for any unwanted usage, such as S3 reads, S3 writes, S3 bucket creates and/or S3 bucket deletes, EC2 instances, Lambda functions, or EC2 Spot bids by logging into your AWS Management Console and reviewing each service page. You can also do this by checking the "Bills" page in the Billing console [8].
Unwanted usage can occur in any region and your console only displays one region at a time. To switch regions, use the drop-down menu in the top-right corner of the console.
Step 4: You must either respond to your TAM/Account Manager or update your existing Support Case [9] to confirm completion of steps 1-3.
If you need help completing the steps to secure your account, please contact your TAM/Account Manager or request a phone call or chat session through the Support Case for immediate assistance. Alternatively, if you believe that your account is secured and there is no inappropriate access or usage, please contact us immediately via the Support Case to confirm this in writing.
Thank you for your immediate attention to this matter.
[1] https://aws.amazon.com/premiumsupport/knowledge-center/potential-account-compromise/
[2] https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_mfa_enable.html
[3] https://console.aws.amazon.com/iam/home#users
[4] https://console.aws.amazon.com/iam/home#security_credential
[5] https://console.aws.amazon.com/iamv2/home#/users
[6] https://console.aws.amazon.com/iam/home#/policies
[7] https://console.aws.amazon.com/iam/home#/roles
[8] https://console.aws.amazon.com/billing/home#/bill
[9] https://console.aws.amazon.com/support/home?#/
Sincerely,
Amazon Web Services
Amazon Web Services, Inc. is a subsidiary of Amazon.com, Inc. Amazon.com is a registered trademark of Amazon.com, Inc. This message was produced and distributed by Amazon Web Services Inc.,
Reference: https://health.aws.amazon.com/health/home#/account/event-log?Event%20ARN=arn:aws:health:global::event/IAM/AWS_IAM_CUSTOMER_ENGAGEMENT/AWS_IAM_CUSTOMER_ENGAGEMENT_A1743_A290E507F31&eventID=arn:aws:health:global::event/IAM/AWS_IAM_CUSTOMER_ENGAGEMENT/AWS_IAM_CUSTOMER_ENGAGEMENT_A1743_A290E507F31&eventTab=details&layout=vertical
Date: 2024年12月11日(水) 19:35
Subject: RE:[CASE 173382692100847] [Action Required] Unexpected Activity Detected on your AWS Account [AWS Account: 582321609766]
Dear AWS Customer,
We are following up with you, as your AWS Account may still be compromised. Please review the previous notice we have sent and take immediate action to secure your account. If you believe that your account is secured and there is no unauthorized access or usage, please contact us immediately by responding to this Support case.
This account compromise poses a security risk to your account (including other account users), and could lead to excessive charges from unauthorized activity. To protect your account from excessive charges, we have temporarily limited your ability to use some AWS services. To remove the limits, please follow the instructions provided in our initial notice.
If the unauthorized usage is not stopped we may suspend your AWS account. To further protect your account from excessive charges, we may terminate any suspected unauthorized resources on your account.
If you have any questions, please contact us by responding through this Support case.
Dear AWS Customer,
We are following up with you, as your AWS Account may still be compromised. Please review the previous notice we have sent and take immediate action to secure your account. If you believe that your account is secured and there is no unauthorized access or usage, please contact us immediately by responding to this Support case.
This account compromise poses a security risk to your account (including other account users), and could lead to excessive charges from unauthorized activity. To protect your account from excessive charges, we have temporarily limited your ability to use some AWS services. To remove the limits, please follow the instructions provided in our initial notice.
If the unauthorized usage is not stopped we may suspend your AWS account. To further protect your account from excessive charges, we may terminate any suspected unauthorized resources on your account.
If you have any questions, please contact us by responding through this Support case.
To share your experience or contact us again about this case, please return to the AWS Support Center using the following URL: https://console.aws.amazon.com/support/home#/case/?displayId=173382692100847&language=en
Note, this e-mail was sent from an address that cannot accept incoming e-mails. To respond to this case, please follow the link above to respond from your AWS Support Center.
===============================================================
Don’t miss messages from AWS Support when you need help! Update your contact information:
https://console.aws.amazon.com/billing/home#/account
If you receive an error message when visiting the contact information page, visit:
https://repost.aws/knowledge-center/iam-billing-access/
AWS Support:
https://repost.aws/knowledge-center/
AWS Documentation:
https://docs.aws.amazon.com/
AWS Cost Management:
https://aws.amazon.com/aws-cost-management/
AWS Training:
http://aws.amazon.com/training/
AWS Managed Services:
https://aws.amazon.com/managed-services/