Settings

Theme

Ask HN: Has AWS Been Hacked?

33 points by drzel 4 years ago · 22 comments · 1 min read

Reader

I just received the following email, to an email address that has only ever been used once, to register an AWS account in 2021.

---- On Thu, 19 May 2022 03:47:29 +1000 Carent Domingo <yourdomainguru.ren49@gmail.com> wrote ----

    Hello,

    My name is Carent from TDS. We have a domain that is currently on sale that you might be interested in - TeamFortress.net
     
    Anytime someone types Team Fortress, Team Fortress Online, The Best Team Fortress, or any other phrase with these keywords into their browser, your site could be the first they see!

    The internet is the most efficient way to acquire new customers

    Avg Google Search Results for this domain is: 68,500,000
    You can easily redirect all the traffic this domain gets to your current site!

    GoDaddy.com appraises this domain at $1,345. 

    Priced at only $398 for a limited time! If interested please go to TeamFortress.net and select Buy Now, or purchase directly at GoDaddy.  
    Act Fast! First person to select Buy Now gets it!  

    Thank you very much for your time.
    Top Domain Sellers (TDS)
    Carent Domingo
sam0x17 4 years ago

This is almost certainly leaking without you realizing it via a WHOIS contact email somewhere or another

Another possibilty is that overseas contractors for AWS regularly harvest email addresses from the support UI and spam them. Wouldn't surprise me, but the first is more likely. Wouldn't really call this a hack though either way.

  • vineyardmike 4 years ago

    > Another possibilty is that overseas contractors for AWS regularly harvest email addresses from the support UI and spam them.

    If this was a practice that was possible and occurring then I suspect we'd have heard of many more cases by now. Most big companies don't use contractors for work that gives them access to customer data like that, and most don't just allow anyone easy access to raw customer data without a paper trail and reason.

    • Nextgrid 4 years ago

      > Most big companies don't use contractors for work that gives them access to customer data like that

      [citation needed]

      Okta is a recent counter-example.

    • izzygonzalez 4 years ago

      What big companies are you referring to? Protecting data takes effort, so by virtue of that, intent is a necessary precondition.

      Most companies probably don't take care of these things at the rate or level you seem to be assuming that they do.

    • sam0x17 4 years ago

      At a previous company AWS was a customer, and I can tell you from the corporate training resources I've seen, they have huge populations of support engineers in countries like India, who are contractors.

    • simplyinfinity 4 years ago

      You would think.. But Epam is a contractor for one of the clouds and has access to client data. Another few (contractor/outsourcing ) companies i know of have access to all their customer's customer data.

gregw2 4 years ago

AWS could be hacked... but the other logical options are your email provider was hacked... or some other PI/hacker who really cares about you (due to team fortress) has figured out your naming pattern from other sources and is probing you, either with or without that domain name company's help?

vineyardmike 4 years ago

Considering you're a developer of a game called "team fortress" (based on your HN comment history) who had a domain for team fortress with WHOIS info updated in 2021, I'd say that its probably someone on your dev team trying to make a few bucks and knew the address. But maybe you registered this with Cloudflare and forgot, and Cloudflare is forwarding the email to you.

  • drzelOP 4 years ago

    I have all those things, but I used a very specific email address for AWS.

    Basically, name+unique_identifier@domain.tld

    The unique_identifier is unique to this AWS account.

YPPH 4 years ago

Are you certain you did not use the email anywhere else, including in WHOIS records for any domain?

Is the email predictable?

I use a dedicated email address for AWS and I have only ever received AWS correspondence to it.

MattGaiser 4 years ago

Did you use this site to register for GoDaddy by any chance? Or for a domain name with AWS that later got transferred to GoDaddy?

Oras 4 years ago

Do you use browser extensions that could collect form data?

throwaway019254 4 years ago

Have you ever had any domain registered with this AWS account?

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection