| Uber |
2014, May |
GitHub Gist (data analysis script) with AWS credentials |
N/A |
50,000 records, including names and driver’s licenses from S3 hosted database prunes |
Exclusive: In lawsuit over hacking, Uber probes IP address assigned to Lyft exec - sources , A blameless post-mortem of USA v. Joseph Sullivan |
| Code Spaces |
2014, June |
AWS Console Credentials (Phishing?) |
Attacker created additional accounts/access keys |
Wiped S3 buckets, EC2 instances, AMIs, EBS snapshots |
Hacker puts code spaces out of business |
| BrowserStack |
2014, November |
Shellshock on exposed, outdated prototype machine |
Access keys on server, used to create IAM user, create EC2, and mount backup |
Steal user data and email users |
BrowserStack analysis |
| DNC Hack by the GRU |
2016, June |
Unknown, test clusters breached |
EC2 Snapshots copied to attacker AWS accounts |
Tableau and Vertica Queries |
DEMOCRATIC NATIONAL COMMITTEE v. THE RUSSIAN FEDERATION |
| DataDog |
2016, July |
CI/CD AWS access key and SSH private key leaked |
Attacker attempted to pivot with customer credentials |
3 EC2 instances and subset of S3 buckets |
2016-07-08 Security Notice |
| Uber |
2016, October |
~13 Hacked Uber credentials purchased for forum gave access to private GitHub Repo with AWS credentials |
N/A |
Names and driver’s license numbers of 600k drivers, PII of 57 million users in unencrypted manual backup |
Uber concealed cyberattack ..., A blameless post-mortem of USA v. Joseph Sullivan |
| Lynda.com |
2016, December |
Private GitHub Repo with AWS credentials |
N/A |
User data for 9.5m users, attempted extortion |
2 Plead Guilty in 2016 Uber and Lynda.com Hacks |
| OneLogin |
2017, May |
AWS keys |
Created EC2 instances |
Accessed database tables (with encrypted data) |
May 31, 2017 Security Incident |
| Politifact |
2017, October |
"Misconfigured cloud computing server" |
N/A |
Coinhive cryptojacking |
Hackers have turned Politifact’s website into a trap for your PC |
| Dataspline |
2017, Unknown |
Monero miner in container base image dependency |
N/A |
Monero cryptojacking |
LinkedIn post from co-founder |
| DXC Technologies |
2017, November |
Private AWS key exposed via GitHub |
244 EC2 instance started |
Cryptomining |
DXC spills AWS private keys on public GitHub |
| Drizly |
2018 |
AWS Credentials committed to public github repo |
N/A |
Cryptojacking |
FEDERAL TRADE COMMISSION - Drizly Complaint |
| LA Times |
2018, February |
S3 global write access |
N/A |
Cryptojacking |
Coinhive cryptojacking added to homicide.latimes.com |
| Tesla |
2018, February |
Globally exposed Kubernetes console, Pod with AWS credentials |
N/A |
Cryptojacking |
Hack Brief: Hackers Enlisted Tesla's Public Cloud to Mine Cryptocurrency |
| Chegg |
2018, April |
Former contractor abuses broadly shared root credential |
Unknown |
40 million users' data (from S3 bucket) |
FTC Complaint |
| imToken |
2018, June |
Email account compromise |
Reset AWS account password |
Minimal customer device data |
Disclosure of Security Incidents on imToken |
| Reddit |
2018, June |
Employee SMS intercepted for 2FA bypass |
N/A |
Internal systems accessed, user data including messages |
We had a security incident. Here's what you need to know. |
| Timehop |
2018, July |
Compromised admin credentials without MFA |
N/A |
21 million users' data including emails, phone numbers, social media tokens |
TechCrunch |
| Voova |
2019, March |
Stolen credentials by former employee |
N/A |
Deleted 23 servers |
Sacked IT guy annihilates 23 of his ex-employer’s AWS servers |
| Capital One |
2019, April |
"Misconfigured WAF" that allowed for a SSRF attack |
Over-privileged EC2 Role |
100 million credit applications |
A Technical Analysis of the Capital One Cloud Misconfiguration Breach |
| JW Player |
2019, September |
Weave Scope (publicly exposed), RCE by design |
N/A |
Cryptojacking |
How A Cryptocurrency Miner Made Its Way onto Our Internal Kubernetes Clusters |
| Malindo Air |
2019, September |
Former employee insider threat |
N/A |
35 million PII records |
Malindo Air: Data Breach Was Inside Job |
| Imperva |
2019, October |
“Internal compute instance” globally accessible, “Contained” AWS API key |
N/A |
RDS snapshot stolen |
Imperva Security Update |
| Cameo |
2020, February |
Credentials in mobile app package |
N/A |
Access to backend infrastructure, including user data |
Celeb Shout-Out App Cameo Exposes Private Videos and User Data |
| Open Exchange Rates |
2020, March |
Third-party compromise exposing access key |
N/A |
User database |
Exchange rate service’s customer details hacked via AWS |
| First Republic Bank |
2020, March |
Fired employee incompletely offboarded |
N/A |
System interruption |
First Republic Bank |
| Live Auctioneers |
2020, July |
Compromised third party software granting access to cloud environment |
N/A |
User database, including MD5 hashed credentials |
Washington State OAG - Live Auctioneers |
| Twilio |
2020, July |
S3 global write access |
N/A |
Magecart2 |
Incident Report: TaskRouter JS SDK Security Incident |
| Natures Basket responsible disclosure |
2020, July |
Hard-coded root keys in source code exposed via public S3 bucket |
N/A |
N/A |
GotRoot! AWS root Account Takeover |
| Drizly |
2020, July |
Inactive GitHub account compromised via reused password, granting AWS credential access in source code |
N/A |
RDS Instance with 2.5 million users data exfiltrated |
FTC Takes Action Against Drizly and its CEO James Cory Rellas for Security Failures that Exposed Data of 2.5 Million Consumers |
| Cryptomining AMI |
2020, August |
Windows 2008 Server Community AMI |
N/A |
Monero miner |
Cryptominer Found Embedded in AWS Community AMI |
| Global Tel*Link (GTL) |
2020, August |
Unprotected test data in AWS cloud |
N/A |
650K users' sensitive data (SSN, DOB, messages) sold on dark web |
FTC Complaint |
| ShopBack |
2020, September |
AWS access key exposed in GitHub commit history |
Modified security settings, created staging database instance |
1.45M users' data including emails, bank accounts, partial credit cards |
PDPC Decision |
| RedMart |
2020, September |
AWS keys embedded in source code in S3 bucket |
N/A |
1.1M users' data (multi-cloud: AWS + Alibaba) |
PDPC Decision |
| Animal Jam |
2020, November |
Slack compromise exposes AWS credentials |
N/A |
User database |
Kids' gaming website Animal Jam breached |
| Cisco |
2020, December |
Former employee with AWS access 5 months post-resignation |
N/A |
Deleted ~450 EC2 instances |
Former Cisco engineer sentenced to prison |
| Juspay |
2021, January |
Compromised old, unrecycled Amazon Web Services (AWS) access key |
N/A |
Masked card data, email IDs and phone numbers |
Data from August Breach of Amazon Partner Juspay Dumped Online |
| MobiKwik |
2021, March |
Compromised AWS access key, S3 bucket accessed |
N/A |
99M users' data, 3.5M KYC documents (Aadhaar, PAN), 8.2TB exfiltrated |
BankInfoSecurity, TechCrunch |
| 20/20 Eye Care Network and Hearing Care Network |
2021, January |
Compromised credential |
N/A |
S3 buckets accessed then deleted |
20/20 Eye Care Network and Hearing Care Network notify 3,253,822 health plan members of breach that deleted contents of AWS buckets |
| Sendtech |
2021, February |
(Current or former employee) Compromised credentials |
Created additional admin account |
Accessed customer data in S3 |
PERSONAL DATA PROTECTION COMMISSION Case No. DP-2102-B7884 |
| Upstox |
2021, April |
Compromised AWS key (ShinyHunters) |
N/A |
2.5M users' KYC data (Aadhaar, PAN, passports, bank accounts) |
The Hacker News |
| LogicGate |
2021, April |
Compromised credentials |
N/A |
Backup files in S3 stolen |
Risk startup LogicGate confirms data breach |
| Ubiquiti |
2021, April |
Compromised credentials from IT employee Lastpass (alleged former employee insider threat) |
N/A |
root administrator access to all AWS accounts, extortion |
Ubiquiti All But Confirms Breach Response Iniquity |
| Uran Company |
2021, July |
Compromised Drupal with API keys |
N/A |
Cryptomining |
Clear and Uncommon Story About Overcoming Issues With AWS |
| MyRepublic |
2021, August |
AWS access key exposed via php-info URL, S3 bucket publicly accessible |
N/A |
79K customers' NRIC/identity documents stolen, extortion |
PDPC Decision |
| reddoorz.com |
2021, September |
Access Key leaked via APK |
N/A |
Customer database stolen |
PERSONAL DATA PROTECTION COMMISSION Case No. DP-2009-B7057 |
| HPE Aruba |
2021, October |
Unknown exposure of Access Key |
N/A |
Potential access to network telemetry and contact trace data |
Aruba Central Security Incident |
| Kaspersky |
2021, November |
Compromised SES token from third party |
N/A |
Phishing attacks |
Kaspersky's stolen Amazon SES token used in Office 365 phishing |
| Illuminate Education |
2021, December |
Stale former employee credentials (3.5 years post-departure) |
AWS security groups modified, database passwords reset, resources deleted |
10.1M students' data exfiltrated from S3/SQL backups |
FTC Action |
| Eye Care Leaders |
2021, December |
Unknown |
Unknown |
deleted databases and system configuration files, potential theft of 1.5M patient records |
Augusta University Health - Breach Disclosure [PDF] |
| Onus |
2021, December |
Log4Shell vulnerability in Cyclos server |
AmazonS3FullAccess creds (and DB creds) in Cyclos config |
2 million ONUS users’ information including EKYC data, personal information, and password hash was leaked. |
The attack on ONUS – A real-life case of the Log4Shell vulnerability |
| Flexbooker |
2021, December |
Unknown |
Unknown |
3.7M first and last names, email addresses, phone numbers, "encrypted" passwords |
Booking management platform FlexBooker leaks 3.7 million user records |
| npm |
2022, April |
Third party OAuth token compromise granting private repository access, containing AWS keys |
Unknown |
100k users data (from 2015) |
npm security update: Attack campaign using stolen OAuth tokens |
| PREMINT |
2022, July |
S3 global write access |
Unknown |
NFT Theft (supply chain) |
Full Analysis of the PREMINT Attack Incident |
| Uber |
2022, September |
Contractor account compromise leading to AWS credential discovery on a shared drive |
Unknown |
N/A |
Uber - Security update |
| Lastpass |
2022, October |
Stole source code and accessed development environment via compromised developer account (an IAM User) |
Unknown pivot point into production environment. Later compromise of a privileged engineer's personal machine to gain access to decryption keys for stolen data |
Internal and customer data broadly compromised, including backups of MFA database |
Notice of Recent Security Incident,Incident 2 – Additional details of the attack, Breaking the Vault: A Case Study of the 2022 LastPass Data Breach |
| FTX |
2022, November |
Private keys in Secrets Manager without HSM protection, GuardDuty not enabled |
Unknown, credentials broadly accessible to employees |
$432M+ cryptocurrency stolen during bankruptcy chaos |
breaches.cloud |
| Medibank |
2022, October |
Compromised credentials |
Unknown |
Data exfiltration from Redshift / "Ransomware" |
Medibank now says hackers accessed all its customers’ personal data, Amazon Redshift gets new default settings to prevent data breaches |
| Sonder |
2022, November |
Unknown |
Unknown |
Theft of customer information, attempted extortion |
Security Update, Breach Notification |
| Teqtivity (Uber Vendor) |
2022, December |
Unknown |
Unknown |
"AWS backup server" with device and user information |
Breach Notification Statement, Uber suffers new data breach after attack on vendor, info leaked online |
| CommuteAir |
2023, January |
Publicly Exposed Jenkins with hardcoded credentials |
N/A |
2019 FAA No Fly List |
how to completely own an airline in 3 easy steps, U.S. airline accidentally exposes ‘No Fly List’ on unsecured server |
| Episource |
2023, February |
Unauthorized access to AWS environment |
Ransomware |
5.4 million healthcare records |
HIPAA Journal |
| Coffee Meets Bagel |
2023, August |
Unknown |
N/A |
Data deletion, 7-day service outage |
The Register |
| Cloudflare |
2023, November |
Pivot from Okta compromise due to un-rotated access token |
N/A |
N/A |
Cloudflare - Thanksgiving 2023 security incident |
| Sumo Logic |
2023, November |
Compromised credential |
N/A |
N/A |
Sumo Logic Security Notice |
| Football Australia |
2024, February |
AWS access key embedded in website HTML |
N/A |
126 S3 buckets, player passports, contracts, ticket buyer data |
breaches.cloud |
| Sisense |
2024, April |
Credentials stolen from Gitlab repository |
N/A |
Terabytes of customer data exfiltrated from S3 |
Why CISA is Warning CISOs About a Breach at Sisense |
| Dropbox Sign |
2024, May |
Service account compromise |
N/A |
Customer authentication data (emails, names, API keys, OAuth tokens) |
A Recent Security Incident Involving Dropbox Sign |
| pcTattletale |
2024, May |
Application vulnerability disclosed root AWS keys |
N/A |
Data published publicly |
Spyware app pcTattletale was hacked and its website defaced, defaced site |
| Quadrant Global |
2024, May |
Jenkins CVE-2024-23897 exploited on EC2 |
AWS access key stolen, S3 bucket accessed |
75K Geolancer app users' data sold on dark web |
PDPC Undertaking |
| FinWise Bank / American First Finance |
2024, May |
Former employee insider threat |
RDS database accessed via residual credentials |
689K customers' SSNs, financial data |
BleepingComputer, The Register |
| Relay Graduate School of Education |
2024, November |
Unknown |
AWS-hosted applications accessed, files deleted |
22,769 student records (PII) |
Breach Notification |
| BeyondTrust |
2024, December |
0day vulnerability in a 3p application |
infrastructure API key to pivot cross-account |
Customer Instances compromised |
BeyondTrust Remote Support SaaS Service Security Investigation |
| TinaCloud |
2024, December |
Credentials leaked in JS file |
N/A |
SES abuse for phishing |
TinaCloud: Public Disclosure of Security Breach |
| Otelier |
2025, January |
Infostealer |
Credentials found in Bitbucket |
8TB of data exfiltrated from S3 |
Otelier data breach exposes info, hotel reservations of millions |
| Gravy Analytics |
2025, January |
Misappropriated AWS access key |
AWS cloud storage accessed |
17TB claimed, 30M+ verified location data points from thousands of apps |
TechCrunch, The Record |
| Bybit / Safe{Wallet} |
2025, February |
Safe{Wallet} developer macOS compromised via social engineering |
Stolen AWS token used to inject malicious JavaScript in S3 bucket |
$1.5 Billion stolen |
Sygnia Case Study, lazarus.day |
| AngelOne |
2025, March |
Unknown |
N/A |
Data exfiltration |
Indian Stock Broker Angel One Discloses Data Breach |
| Pearson |
2025, March |
Exposed GitLab token in .git/config |
AWS credentials in source code |
Data exfiltration |
Education giant Pearson hit by cyberattack exposing customer data |
| BitoPro |
2025, May |
Social engineering of cloud ops employee, malware |
AWS session token hijacked to bypass MFA |
$11M cryptocurrency stolen |
BleepingComputer, lazarus.day |
| KiranaPro |
2025, June |
Former employee, post layoff |
N/A |
Service disruption |
Indian grocery startup KiranaPro was hacked and its servers deleted, CEO confirms, KiranaPro Crisis Explained: Ex-Employee’s Revenge Move that Paralysed the App |
| Salesloft (Drift) |
2025, August |
GitHub repository compromise (UNC6395) |
AWS environment accessed, OAuth tokens stolen |
700+ Salesforce instances compromised |
Google Cloud, Salesloft Security Update |
| Kodex |
2025, October |
Fraudulent legal domain transfer order |
N/A |
Outage when domain frozen |
Subpoena tracking platform blames outage on AWS social engineering attack |
| Kiln |
2025, October |
Compromised GitHub Access Token |
Credentials stolen from GitHub Actions, modify running API logic |
Cryptocurrency theft |
Re-enablement of Kiln services and security incident information |
| Eurail B.V. |
2025, December |
Unknown |
S3, Zendesk, GitLab accessed |
308,777 travelers' data (passports, addresses) stolen, 1.3TB exfiltrated |
SecurityWeek, Cybernews |
| Aesto Health |
2025, December |
Unknown |
AWS infrastructure accessed |
9.5M patient records (PHI, SSNs, medical records, financial data) |
Breach Disclosure |
| つくるAI (Tsukuru AI) |
2026, February |
Credentials stolen |
N/A |
AWS SES abused for 176K spam emails |
Security NEXT, Company site |
| LexisNexis |
2026, February |
Unpatched React2Shell vulnerability (CVE-2025-55182) |
AWS Secrets Manager, Redshift, VPC databases accessed |
2GB data including ~400K user profiles |
LexisNexis Legal & Professional confirms data breach |
| CareCloud |
2026, March |
Unknown |
AWS environment accessed |
3.75M individuals' medical, financial, and identity data |
Breach Notification, TechCrunch |
| BuddyBoss |
2026, March |
CI/CD pipeline compromise via malicious GitHub Actions workflow |
SSH credentials stolen, root access on AWS server, SSH key persistence |
246+ WordPress sites compromised via supply chain attack |
Ctrl-Alt-Intel - The BuddyBoss Attack: Full Incident Analysis |
| European Commission |
2026, March |
Trivy supply chain compromise (CVE-2026-33634) |
AWS API key stolen from CI/CD |
340GB data from 71 EU entities, 52K email files |
CERT-EU - European Commission hack exposes data of 30 EU entities |
| Resolv Labs |
2026, March |
AWS KMS compromise (suspected Cisco firewall CVE-2026-20131) |
KMS signing key access |
$23-25M stolen via unauthorized USR stablecoin minting |
Halborn - Explained: The Resolv Hack |
| Cisco |
2026, April |
Trivy supply chain compromise (CVE-2026-33634) |
AWS keys stolen, unauthorized cloud account access |
300+ repos exfiltrated (AI projects, customer data) |
SANS ISC - TeamPCP Supply Chain Campaign Update 007 |
| Porter |
2026, April |
Stale, overprivileged AWS access key |
IAM role chaining to customer accounts |
21 customer accounts accessed, 3 GitHub repos cloned, secrets exposed |
Porter Security Incident Disclosure |
| Context.ai |
2026, April |
Infostealer on employee device (Lumma Stealer) |
AWS environment accessed, OAuth tokens stolen enabling downstream Vercel breach |
Customer OAuth tokens compromised, downstream access to Vercel employee accounts |
Context.ai Security Update, Vercel Bulletin |
| Braintrust |
2026, May |
Unknown (under investigation) |
N/A |
Customer API keys for AI models exposed |
TechCrunch - Braintrust confirms breach |
| Arup Group |
2026, May |
GitHub personal access token in JavaScript file |
AWS S3, Azure Blob, GitLab accessed |
2TB cloud data, 700GB repos, HS2 rail project files |
BushidoToken, BrinzTech |
| Beacon |
2026, July |
AWS access key exposed in public JavaScript build artifacts |
Database backups accessed |
Full database copy with customer data exfiltrated |
Security Incident |
| Hugging Face |
2026, July |
HDF5 file read + Jinja2 template injection (exploited by autonomous AI agent) |
IMDS credential theft, EKS node root, VPN pivot |
AWS keys and credentials compromised, 5 datasets accessed |
Technical Timeline of the July 2026 Incident |
| JetBrains Cadence |
2026, August |
Unpatched TeamCity vulnerability (CVE-2026-63077) |
IAM credentials compromised, S3 buckets accessed |
Personal data, 2024 backup with credentials, customer cloud credentials and source code |
Security Incident Affecting JetBrains Cadence |
| MyDr |
2026, August |
XXE vulnerability in PKCS#12 certificate handling (RCE) |
GitHub API key stolen, source code accessed, AWS infrastructure compromised |
2.5TB data, 19M patient records (PESEL, prescriptions, medical notes) from 12K+ facilities |
The Record, GovInfoSecurity |