Sunday, 1 Mar 2026
Subscribe
logo
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Font ResizerAa
Data Center NewsData Center News
Search
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Data Center News > Blog > Global Market > Ransomware gangs seize a new hostage: your AWS S3 buckets
Global Market

Ransomware gangs seize a new hostage: your AWS S3 buckets

Last updated: November 23, 2025 6:48 pm
Published November 23, 2025
Share
cloud technology protection information cybersecurity indentity
SHARE

To succeed, attackers usually search for S3 buckets which have: versioning disabled ( so outdated variations can’t be restored), object-lock disabled ( so recordsdata could be overwritten or deleted), extensive write permissions (by way of mis-configured IAM insurance policies or leaked credentials), and maintain high-value knowledge (backup recordsdata, manufacturing config dumps).

As soon as inside, the attackers attempt to impose a “full and irreversible lockout” of information, which can contain encryption objects with keys inaccessible to the sufferer, deleting backups, and scheduling key deletion so AWS and the client can’t get better the info.

“This analysis is a scientific and theoretical risk modelling train on how an attacker may encrypt and ransom an AWS setting inside an account boundary–one thing we’ve talked about over the past 10 years,” mentioned Trey Ford, chief technique and belief officer at Bugcrowd.

Weaponizing cloud encryption and key administration

Development Micro has identified 5 S3 ransomware variants that more and more exploit AWS’s built-in encryption paths. One abuses default AWS-managed KMS keys (SSE-KMS) by encrypting knowledge with an attacker-created key and scheduling that key for deletion. One other makes use of customer-provided keys (SSE-C), the place AWS has no copy, making restoration inconceivable. The third one exfiltrates S3 bucket knowledge (with no versioning) and deletes the originals.

The ultimate two variants go deeper into key administration infrastructure. One depends on imported key materials (BYOK), letting attackers encrypt knowledge after which destroy or expire the imported keys. The opposite abuses AWS’s Exterior Key Retailer (XKS), the place key operations occur exterior AWS, which signifies that if attackers management the exterior key supply, neither the client nor AWS can restore entry. Collectively, the methods reveal that attackers are utilizing AWS itself because the encryption mechanism.

See also  Amazon’s AWS Shows Signs of Weakness as Competitors Charge Ahead

“I can’t recall having seen this executed within the wild,” Ford added. “This particularly targets the usage of exterior or customer-provided keys (SSE-C or XKS, respectively) to claim management over key administration for the cryptography utilized in storage.”

Source link

TAGGED: AWS, buckets, gangs, hostage, ransomware, seize
Share This Article
Twitter Email Copy Link Print
Previous Article Google’s ‘Nested Learning’ paradigm could solve AI's memory and continual learning problem Google’s ‘Nested Learning’ paradigm could solve AI's memory and continual learning problem
Next Article Mitigating business data accuracy threats Mitigating business data accuracy threats
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Your Trusted Source for Accurate and Timely Updates!

Our commitment to accuracy, impartiality, and delivering breaking news as it happens has earned us the trust of a vast audience. Stay ahead with real-time updates on the latest events, trends.
FacebookLike
TwitterFollow
InstagramFollow
YoutubeSubscribe
LinkedInFollow
MediumFollow
- Advertisement -
Ad image

Popular Posts

Liquid-cooled server components put to the test

Environment friendly cooling of server racks (colocation) is essential for knowledge facilities as a way…

June 18, 2024

Allo Secures $100M in Debt Financing

Allo CEO Kingsley Advani Allo.xyz, a Dubai, UAE-based platform for real-world asset (RWA) tokenization and…

December 25, 2024

XTX Markets partners with YIT for second data center in Finland

YIT and XTX Markets have prolonged their enterprise, initiating the development of a second knowledge…

August 13, 2025

Copley Raises $4.8M in Funding

Copley Software, a Boston, MA-based AI-powered content material experimentation and optimization startup, raised $4.8M in…

March 5, 2025

Nvidia introduces ‘ridesharing for AI’ with DGX Cloud Lepton

The platform is at the moment in early entry however already CoreWeave, Crusoe, Firmus, Foxconn,…

May 19, 2025

You Might Also Like

Data center / enterprise networking
Global Market

HPE’s latest Juniper routers target large‑scale AI fabrics

By saad
Panoramic high speed technology in big city concept, light abstract background.
Global Market

Netskope targets AI-driven network bottlenecks with AI Fast Path

By saad
H1 2026 - Data Centre Review
Global Market

H1 2026 – Data Centre Review

By saad
Juniper Networks
Global Market

Security hole could let hackers take over Juniper Networks PTX core routers

By saad
Data Center News
Facebook Twitter Youtube Instagram Linkedin

About US

Data Center News: Stay informed on the pulse of data centers. Latest updates, tech trends, and industry insights—all in one place. Elevate your data infrastructure knowledge.

Top Categories
  • Global Market
  • Infrastructure
  • Innovations
  • Investments
Usefull Links
  • Home
  • Contact
  • Privacy Policy
  • Terms & Conditions

© 2024 – datacenternews.tech – All rights reserved

Welcome Back!

Sign in to your account

Lost your password?
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.
You can revoke your consent any time using the Revoke consent button.