AI-Assisted Attack Breaches AWS Cloud in Under 10 Minutes

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

On November 28, 2025, attackers used large language models (LLMs) to automate and accelerate a cyberattack on an Amazon Web Services (AWS) environment. Leveraging AI for reconnaissance, code generation, and privilege escalation, they achieved full administrative access in under 10 minutes, compromising cloud infrastructure and security.[AI generated]

Why's our monitor labelling this an incident or hazard?

The event involves the use of AI systems (large language models) to assist in a cyberattack that directly led to harm, including unauthorized access to sensitive data and administrative control over cloud resources. This constitutes a violation of security and privacy rights, harm to property (data and cloud infrastructure), and disruption of cloud environment management. The AI system's role was central in automating and accelerating the attack, making this an AI Incident under the framework definitions.[AI generated]
AI principles
SafetyRobustness & digital security

Industries
IT infrastructure and hostingDigital security

Affected stakeholders
Business

Harm types
Economic/PropertyReputational

Business function:
ICT management and information security

AI system task:
Content generationReasoning with knowledge structures/planning


Articles about this incident or hazard