Attackers Hijack AWS Bedrock Access Using Stolen IAM Credentials

Summary
Fortinet reports an AWS compromise in which a leaked, long-lived administrator IAM key was used to create an identity, subscribe to foundation models through Marketplace, and invoke them, charging inference costs to the victim. The article outlines logging and identity-
Key points
- A leaked, long-lived AWS IAM key with AdministratorAccess was used to compromise an account.
- The operator created a new IAM user, subscribed to foundation models through AWS Marketplace, and invoked them, generating charges for the victim.
- LLMjacking abuses valid cloud credentials to consume hosted AI inference, with access potentially resold to others.
- The activity can resemble legitimate API use; Fortinet recommends corroborating first-time Bedrock use with signals such as new identities or unfamiliar IPs.
- Enable CloudTrail and, where feasible, Bedrock invocation logging; prefer short-lived, role-assumed credentials over broad, long-lived keys.
- Fortinet lists detections covering IAM changes, new users, Marketplace agreements, Bedrock invocation logging, and service-specific credentials; several policies require explicit enablement.
Article Details
- Attack Vectors
- In the investigated incident, a leaked, long-lived IAM access key with AdministratorAccess permissions enabled compromise of an AWS account.
- The operator created a new IAM user, subscribed to foundation models through CreateAgreementRequest/AcceptAgreementRequest, and invoked those models at the victim account's expense.
- The article describes service-specific credential issuance for the new identity as a typical additional step in this attack class, not a confirmed step in the investigated incident.
- The article identifies leaked access keys, exposed CI/CD secrets, and stolen local credentials as general prerequisites for this form of abuse. Hijacked inference access can be used directly or resold; resale was not confirmed in the investigated incident.
- Defensive Notes
- Enable CloudTrail on every account to reconstruct identity creation, credential issuance, subscriptions, and their sequence.
- Enable Bedrock invocation logging where feasible. It is disabled by default and captures request-level details not captured by CloudTrail alone.
- Treat long-lived IAM keys with broad permissions as tier-0 risks and prefer short-lived, role-assumed credentials where workloads permit.
- Corroborate first-time Bedrock usage with additional signals such as a new identity, unfamiliar IP, enumeration behavior, or access-denied events rather than treating new usage alone as malicious.
- Default-enabled, high-severity detections include lacework-global-12 for IAM policy changes, lacework-global-13 for traditional access-key changes, and lacework-global-2037 for deletion of Bedrock invocation logging.
- Default-enabled, medium-severity detections include lacework-global-2906 for marketplace agreement creation or acceptance and lacework-global-2907 for service-specific credential creation or reset. Traditional access-key detection does not cover the separate service-specific credential API.
- The default-enabled, medium-severity lacework-global-2038 detection alerts on individual Bedrock ThrottlingException events, not a volume threshold.
- Explicitly enable lacework-global-14, the new-user detection, for accounts running AI workloads; it is available but disabled by default.
- Explicitly enable Bedrock configuration policies lacework-global-1999 through 2002 and 2781 for accounts with Bedrock access. They do not require CloudTrail integration and need explicit enablement or inclusion in a custom framework to appear in compliance reporting.
MITRE ATT&CK
T1078.004 · Cloud AccountsThe operator used a leaked, long-lived AWS IAM access key with AdministratorAccess permissions to compromise the account and access paid model services.T1098.003 · Additional Cloud RolesThe article identifies attaching AdministratorAccess to an identity as the privilege-escalation step that enabled downstream activity in this case.T1136.003 · Cloud AccountThe operator created a new IAM user in the compromised AWS account before subscribing to and invoking foundation models.T1496 · Resource HijackingThe operator invoked paid foundation models through the compromised account, consuming inference resources and generating charges for the victim.
People
Vendors
Products
Amazon BedrockAffected Platforms: Amazon Web Services (AWS), Amazon BedrockAmazon Web Services (AWS)Affected Platforms: Amazon Web Services (AWS), Amazon BedrockAWS MarketplaceThey can instead subscribe to foundation models through AWS Marketplace and resell inference access, a technique called LLMjacking, first documented in 2024.Claude 2.xis not cheap at scale. LLMjacking research puts victim exposure at over $46,000 per day for a Claude 2.x-class inference and past $100,000 per day once attackers move to Claude 3 Opus. Some campaigns resellClaude 3 Opus$46,000 per day for a Claude 2.x-class inference and past $100,000 per day once attackers move to Claude 3 Opus. Some campaigns resell stolen access as a subscription "AI chatbot" service to third parties who haveCloudTrailEnable CloudTrail on every account. It's what turns a suspicious signal into a full picture: who created the identity, what credentials it issued, what it subscribed to, and in what order.FortiCNAPPFortiCNAPP recently investigated a case that shows how fast and mechanical that pivot has become.FortiGuard IP Reputation and Anti-Botnet Security ServiceFortiGuard IP Reputation and Anti-Botnet Security Service proactively block attacks by aggregating malicious source IP data from Fortinet’s distributed network of global sensors, CERTs, MITRE, cooperative partners, andLaceworkFortiCNAPP (Lacework) ships detection coverage relevant to this attack chain: