跳至內容

My s3 account was hacked and they deleted all the data and left a note

0

My s3 account was hacked and they deleted all the data and left a note, they want me to pay, how can I get files :(

To recover your lost files and avoid leaking it: In case of ignoring this message, all personal data will be published publicly open to everyone as well as traded on the Darknet. We will be the ones to mass mail all your clients with all links to where their personal data is open and traded.

Send us 0.3 Bitcoin (BTC) to our Bitcoin addresses Price is not standard, depend on your data.

Contact us by email to confirm awsrecovery@repairman.com

已提問 2 年前檢視次數 437 次

2 個答案
1

Hello.

Did you perform versioning settings or backup settings with AWS Backup on your S3 bucket?
If these settings are not made and objects in the S3 bucket are deleted, it will be impossible to restore them unless the original data is managed on a local PC.
https://docs.aws.amazon.com/AmazonS3/latest/userguide/Versioning.html
https://docs.aws.amazon.com/aws-backup/latest/devguide/s3-backups.html

Also, never comply with the attacker's demands.
Your data will not be recovered even if you comply with the attacker's requests.

Also, identify IAM users used for unauthorized access from CloudTrail event history and delete them immediately.
https://repost.aws/knowledge-center/potential-account-compromise

專家

已回答 2 年前

專家

已審閱 2 年前

1

First and foremost, don't listen to bad actors as data wouldn't be recovered regardless. Start following the best practices to secure your AWS account and resources.

As mentioned above, there are some s3 bucket best practices, one must follow and couple of them I'd like to highlight here:

  • Enable Versioning and have backups
  • Bucket policy must be strict enough, even if someone gets into account, he/she should not have delete access(some sort of DenyAllExcept)

Reference for making your account and resources more secure:

AWS
專家

已回答 2 年前

AWS
專家

已審閱 2 年前

您尚未登入。 登入 去張貼答案。

一個好的回答可以清楚地回答問題並提供建設性的意見回饋,同時有助於提問者的專業成長。