Our AWS account was suspended after suspected unauthorized access or compromised access keys. AWS asked us to reset the root password and update the expired payment method, and we completed both steps before replying to the original support case.
After more than 24 hours without a response, we opened a follow-up case, but it was closed with instructions to continue using the original case. The original case then changed from an AWS action or resolving state to unassigned. We have now gone more than three days without a response, and the account page says "The account is closed." Production services have been unavailable for six days.
Phone support repeatedly returns "Unable to initiate call at this time," while chat either fails to connect or remains waiting. We also opened an escalation case referencing the original one, but it has not received a response after more than 20 hours.
We are not trying to bypass the security review. We want the case assigned, confirmation of whether the account is still eligible for reopening, and instructions for any remaining remediation. If the account cannot be restored, our priority is getting access to the S3 data so it can be migrated to another account.
Has anyone dealt with a reinstatement or security case becoming unassigned after completing AWS's requested steps? Are there any legitimate escalation options beyond replying to the case, opening a related case, or trying phone and chat support?
4 Answers
If this account supports production, the support tier matters. Basic support may not provide a fast human escalation path for an account-security incident. For the future, consider a paid support plan and a documented backup or migration strategy instead of relying on a single account.
Do not delay if the account is still in a post-closure or recovery window. Keep replying to the original case with a concise timeline, confirmation that every requested step is complete, the business impact, and a direct request for assignment to the account-security team. Preserve copies of all case messages and keep trying the official support channels.
A technical account manager is another possible route for customers who have one, but not having one does not mean the case is hopeless. Since you do not have a TAM, continue using the original case rather than creating many unrelated tickets, and reference the case number consistently in any official escalation. Also prepare for migration by maintaining independent backups of critical data where possible.
We do not have a TAM and have been working only through support cases. Someone familiar with AWS informally checked and was told the case appeared to be awaiting follow-up, even though we had already completed the requested actions and replied.
The suspension was caused by suspected unauthorized access, while the payment-method update was an additional requirement from support. The payment was completed successfully, so those are separate issues rather than conflicting explanations.

We were on the default support level because the account mainly contained S3 buckets. This incident showed us that we need a paid support plan, but right now we mainly need either reinstatement or a way to retrieve the data and move it elsewhere.