Decision RecordActivePublished without chair review
CRT-2026-025201 Sep 2026AFTERNOON EDITIONDaily Roundtable
Protect and monitor AWS root accounts
Require phishing-resistant protection for management-account root users, remove unnecessary root credentials and access keys, alert on every root event, and escalate unexpected successful authentication or subsequent root activity to incident response.
Current public guidance · the full record
What to do now
At a glanceThe edition's authoritative action board carries no action for this record's subjects — no What to do now guidance.
Why now
SupportedThe bounded record, current through September 1, 2026, reports coordinated failed authentication against AWS root users at more than 150 organizations from July 24 through August 23, 2026.
Source infrastructure spanned multiple countries and ASNs and included hosting and residential-proxy services.
Although no successful compromise was identified, the campaign creates an immediate need to verify root protections and CloudTrail coverage so unexpected success or later root activity is detected and escalated.
Who is affected
Partially supportedThe observed population is more than 150 organizations whose AWS root users received repeated failed authentication attempts from July 24 through August 23, 2026; the evidence identifies campaign exposure but no successful compromise.
Operators of AWS management accounts with unnecessary root credentials, root access keys, or missing phishing-resistant protection must remediate those configurations.
Identity, security-monitoring, and incident-response teams responsible for CloudTrail must distinguish failed ConsoleLogin activity from unexpected success or subsequent root activity and escalate the latter.
No package, software version, or AWS release is identified; the scope is AWS management-account root configuration and telemetry.
What supports this
Partially supportedThe identity architect’s campaign analysis supports the decision: it reports repeated failed authentication against AWS root users at more than 150 organizations from July 24 through August 23, 2026, across multiple countries and ASNs, with no identified successful compromise.
The moderator’s synthesis also supports it: it classifies the activity as coordinated password spraying rather than proven access and identifies CloudTrail as the boundary between failures and unexpected success.
The final synthesis provides contextual support by classifying AWS root spraying as requiring a distinct identity response.
The evidence assessment directly supports phishing-resistant root protection, removal of unnecessary root credentials and access keys, alerting on every root event, and incident-response escalation after unexpected success or subsequent root activity.
How the Roundtable reached this
Partially supportedThe identity analysis surfaced coordinated AWS root-user spraying but distinguished failed attempts from credential acceptance.
The moderator used CloudTrail as the decision boundary: failures alone remain campaign evidence, while unexpected successful authentication or subsequent root activity triggers incident response.
The evidence check supported phishing-resistant protection, credential removal, root-event alerting, and that escalation threshold. The boundary assessment found the distinction publicly supportable.
A bounded record comparison found no prior matching decision, and the arbiter selected a new operational action.
Positions are generated by AI specialist personas and chaired by Halil Öztürkci.
Panel composition
- Scout (AI panel role)Scout identified 7 candidate signals.
- Linker (AI panel role)Linker evaluated 7 relation judgments.
- Evidence Auditor (AI panel role)Evidence Auditor recorded 15 evidence signals; 8 gaps.
- Prediction Steward (AI panel role)Prediction Steward accepted 1 prediction and rejected 1 claim.
- Boundary Reviewer (AI panel role)Boundary Reviewer recorded 11 public/private findings.
- Arbiter (AI panel role)Arbiter produced 7 decision envelopes.
Key disagreement
Scout (AI panel role)
Failures alone do not prove credential acceptance or justify estate-wide rotation, and a generic authentication failure may not reveal which authentication step failed.
Arbiter outcome
Arbiter outcome: new decision record. The evidence strongly supports the proposed root-account protections, telemetry, and escalation thresholds while distinguishing failed spraying from confirmed compromise.
Candidates considered
Considered 7 candidates · opened 1 · 6 not opened (6 other)
Considered, not opened
Sign in to preview Considered-Not-Opened entries (moves to Pro at launch).
Sign in to preview practitioner entries.
What is uncertain
ConflictingA generic authentication failure may not reveal which authentication step failed, so the record cannot establish whether any sprayed password was correct.
It also cannot establish that every targeted account had complete CloudTrail coverage or exclude activity after the September 1, 2026 replay cutoff.
No successful compromise was identified in the cited campaign evidence, but account-specific compromise can be excluded only with complete authentication and subsequent root-activity records.
What evidence is missing
Partially supportedThe bounded material does not include the direct Datadog incident report, raw authentication events, per-account CloudTrail records, or a direct AWS advisory. It also lacks account-specific evidence about credential reuse or exposure, the authentication step that failed, later successful logins, root API activity, session state, telemetry completeness, and current inventories of root credentials, access keys, and phishing-resistant protection.
What would change this
Partially supportedEvidence of unexpected successful AWS root authentication or subsequent root activity would change the response from failed-spray monitoring to incident response.
Credential reuse, known exposure, root API activity, or incomplete telemetry would trigger credential rotation and session invalidation because compromise could not be excluded.
Complete CloudTrail evidence showing only failures and no later root activity would support continued monitoring without estate-wide rotation based solely on the spraying. Direct AWS guidance or primary incident data could refine the controls or escalation threshold.
What to watch next
Partially supportedMonitor every AWS root ConsoleLogin result and all subsequent root activity in CloudTrail.
Escalate immediately on an unexpected successful authentication, root API activity, evidence of credential reuse or exposure, or a telemetry gap that prevents excluding compromise.
Track incident evidence published after the September 1, 2026 replay cutoff; confirmed successful access would replace the failed-spraying assessment with an active compromise response.
Evidence basis
Summary: PaperCut remains the immediate priority because public exploit availability and observed intrusions materially increase compromise risk. Rails exploitation confirms file-read activity, not unconditional RCE, while the Packagist cam…
The AWS campaign sharpened an essential distinction: broad, geographically distributed root-account failures show coordinated password spraying, not successful access. Datadog observed repeated failures affecting more than 150 organizations…
**Confirmed campaign evidence:** Datadog observed repeated failed authentication attempts against AWS root users at more than 150 organizations from July 24 through August 23, 2026. The source addresses spanned many countries and ASNs and w…
Public value history
- 01 Sep 2026Initial public guidanceCurrent guidance
Created the first public value version for this Decision Record.
Source RoundtableAfternoon roundtableConvened 01 Sep 2026Methodology
How the panel reaches a Public Decision Record.