Skip to content

Keep receiving mails that my account is compromised

0

I've changed the password but I keep getting mails that my account will be suspended if I don't do something Please help thanks.

asked a year ago458 views
3 Answers
0

Hello.

Didn't the email mention anything you needed to do other than changing your AWS account password?
If it is not specifically mentioned, please first check the contents of the following document.
After checking, check if there are any remaining AWS resources that were used for unauthorized use or IAM resources that were used for unauthorized access, and if any remain, please delete them.
https://repost.aws/knowledge-center/potential-account-compromise
https://docs.aws.amazon.com/whitepapers/latest/aws-security-incident-response-guide/aws-security-incident-response-guide.html

EXPERT
answered a year ago
EXPERT
reviewed a year ago
  • This is the mail: Hello,

    We are reaching out to you because your AWS Account may have been inappropriately accessed by a third-party. Please review this notice and take immediate action to secure and restore your account.

    To protect your account, we have temporarily limited your ability to use some AWS services.

    To restore access, you must contact AWS within (5) days and follow the instructions below. If you do not contact AWS within (5) days, we may suspend your account. We may terminate any suspicious resources on your account, and some resources may not be recoverable once terminated.

    We strongly recommend you follow the instructions below to secure and restore your account. For more detailed instructions, please refer to the “What do I do if I notice unauthorized activity in my AWS account?” user guide [1].

    Step 1: Change your AWS root account password You can refer to “Changing the AWS account root user password” user guide [2] for more information.

    As a security best practice, we encourage you to create a password that is unique and not used for any other services. If you previously used the same password for your e-mail provider, we recommend you also change the password of your e-mail account as soon as possible.

    Step 2: Enable multi-factor authentication (MFA) on your AWS root user to create an additional layer of protection for your account [3].

    Step 3: Check your CloudTrail log for unwanted activity Check your account for any unwanted activity, such as the

  • If the necessary measures have been completed, please reply to the email to inform AWS that the measures have been completed.

  • The mail is no-reply-aws@amazon.com So I cant reply

0

Enter image description here
Enter image description here Enter image description here
Enter image description here

answered a year ago
0

Enter image description here

answered a year ago

You are not logged in. Log in to post an answer.

A good answer clearly answers the question and provides constructive feedback and encourages professional growth in the question asker.