AWS automatically attaches the managed AWSCompromisedKeyQuarantine policy to an IAM user after detecting that the user’s long-term access key and secret were publicly exposed. A controlled GitHub exposure test showed the AWSCompromisedKeyQuarantineV3 policy applied within 10 seconds, followed by a GitHub notification, AWS Health alert, email notification, and AWS Support case. The policy uses explicit deny statements to block high-risk activity while retaining much of the user’s ordinary access.
The quarantine policy has expanded from 28 denied actions across five services in 2020 to restrictions spanning resource creation and services including Amazon S3, EC2, IAM, and Bedrock, reflecting evolving cloud-abuse tactics. Organizations should investigate CloudTrail AttachUserPolicy events involving this policy and GitHub secret-validation GetCallerIdentity requests, then rotate exposed credentials, assess activity performed before containment, and enforce least-privilege IAM controls; permissions not explicitly denied may remain available to an attacker.

See attribution, scope, and your downstream exposure.
11 events from the most recent confirmed update back to the earliest known activity.
AWS sent an email notification and subsequently created an AWS Support case containing details of the exposed access key and affected IAM user. Support-case creation did not generate a CloudTrail event in the test.
AWS created a Risk IAM quarantine AWS Health alert after detecting the exposed credentials. The Health-alert creation did not produce a CloudTrail event in the test.
GitHub sent an exposed-secret notification one second after AWS attached the quarantine policy to the affected IAM user.
Ten seconds after the public GitHub exposure, AWS attached AWSCompromisedKeyQuarantineV3 to TestUser through an IAM AttachUserPolicy event. The CloudTrail event's userIdentity field identified TestUser even though that user did not perform the attachment.
The test access key and secret were successfully pushed to a public GitHub repository. GitHub push protection had detected the credentials before the public push.
A controlled exposure test created an IAM user named TestUser and an access key for that user.
AWS released AWSCompromisedKeyQuarantineV2 version 5, adding restrictions affecting services including ECS, ECR, Bedrock, S3, SageMaker, SES, STS, Amplify, CodeBuild, Glue, IAM, Lambda, SNS, and MediaPackage v2.
AWS released AWSCompromisedKeyQuarantineV3. Its first version matched V2 version 4, while its second version matched V2 version 5.
AWS released AWSCompromisedKeyQuarantineV2, which ultimately grew through five revisions to deny 61 permissions across 17 AWS services.
AWS created the initial AWSCompromisedKeyQuarantine managed IAM policy. It denied 28 actions across IAM, EC2, AWS Organizations, Lambda, and Lightsail to limit abuse of exposed access keys.
GitHub added AWS to its secret-scanning partner program, enabling scanning of public GitHub repositories and public npm packages for AWS credential patterns.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
4 references tracked. Mallory keeps watching after this page renders.
unit42.paloaltonetworks.com
Open sourcedocs.aws.amazon.com
Open sourceaws.amazon.com
Open sourcedocs.aws.amazon.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.