Amazon Cognito multi-Region replication (MRR) now lets organizations replicate a primary user pool to one replica AWS Region for near-real-time user synchronization and authentication failover. The primary pool remains authoritative, while replicas support authentication, token issuance and revocation, and selected read-only operations; configuration and user-attribute writes are not available in the replica. Sessions and JWTs are interoperable between Regions, and deployments require a symmetric multi-Region customer-managed AWS KMS key.
AWS recommends using Cognito’s multi-Region OIDC issuer so OIDC discovery and JWKS endpoints remain reachable during a regional impairment, with Route 53 health checks used to automate domain failover. Organizations should deploy equivalent regional dependencies—including Lambda triggers, AWS WAF, SNS, SES, and monitoring—and validate failover through health-check inversion and AWS Fault Injection Service. Security teams must also account for independent replica quotas, data-residency requirements, and the lack of TOTP MFA support in replica pools while preserving OpenID Connect controls such as TLS, signed JWT validation, nonce protection, and exact redirect-URI validation.

See real exploitation activity before you spend the cycle.
1 event from the most recent confirmed update back to the earliest known activity.
AWS described Amazon Cognito multi-Region replication, which synchronizes a primary user pool with one replica Region for authentication failover while retaining the primary pool as authoritative for configuration and user-attribute writes. The guidance covers multi-Region KMS keys, interoperable sessions and JWTs, multi-Region OIDC issuers, Route 53-driven failover, and replica limitations including unsupported TOTP MFA.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
aws.amazon.com
Open sourcedocs.aws.amazon.com
Open sourceopenid.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.