Our AWS account was suspended after suspected unauthorized access and potentially compromised access keys. Support instructed us to reset the root password and update the expired payment method, and we completed both steps before replying to the original case. The payment method is valid and the latest payment succeeded.
After more than 24 hours without a response, we opened a follow-up case, but it was closed with instructions to continue using the original case. The original case then changed from an AWS-resolving status to unassigned, and we have now gone several days without a response. The account page says the account is closed, while production services have been unavailable for six days.
Phone support repeatedly fails with "Unable to initiate call at this time," and chat either does not connect or remains waiting. We also opened an escalation case referencing the original one, but it has not received a response.
We are willing to complete any additional security remediation. We mainly need AWS to confirm whether the account can still be reopened, assign the case to someone, or explain how we can recover the data from our S3 buckets and move it to another account. We were using the basic support level and do not have a technical account manager. What legitimate escalation options are available beyond replying to the existing case, opening related cases, and trying phone or chat support?
4 Answers
The lack of a paid support plan may limit response options and escalation speed, especially for a production outage. Still, opening multiple duplicate cases usually will not help if AWS has directed you back to the original security case. Continue documenting every attempted contact and ask specifically for an account-reinstatement or post-closure review, rather than opening general technical-support requests. If access is restored, move the workloads and data to a separate account and set up a higher support tier and stronger access controls.
Make sure the case clearly distinguishes the security incident from the billing requirement. The account was suspended because of suspected unauthorized access, while updating the payment method was simply a condition Support gave you for continuing the review. State that the card is valid, the payment succeeded, the root password was reset, and all requested steps were completed. Keep replying to the original case so the full history stays together, and include a concise timeline and the exact impact on production.
Since phone and chat are failing, use every official contact form or account-recovery path available from the provider’s public support pages, and reference the original case number in each submission. Include the account ID, business impact, completed verification steps, and a request for a human owner to be assigned. Avoid sending credentials, secret keys, or other sensitive material in a case message.
Treat the data-recovery question as a separate priority. Ask Support explicitly whether the account is inside the permitted reopening period and whether they can provide temporary access or an approved process for exporting the S3 data. Do not try to work around the suspension or create access paths that could look like an attempt to bypass the security review. Also verify that you have backups outside the affected account, because closed-account retention periods may be limited.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures