My AWS account was compromised on September 16. I detected it quickly, changed the root password, replaced credentials and MFA, reviewed CloudTrail, audited IAM users, roles, policies, and credentials, and checked for unauthorized resources or activity. I also contacted AWS at the time.
AWS did not respond until September 24, when they opened a case stating that the account may have been accessed improperly. They restricted access to some services and instructed me to perform the same security checks I had already completed. I confirmed on September 25 that the account had been secured and that all requested remediation was done.
It is now October 1, and Lambda execution remains restricted. I have updated the support case daily but have received no substantive response. The account is still under development, so there has been no production outage, but I am concerned that there is no clear SLA or escalation process for removing an AWS-imposed security restriction after remediation is complete.
Has anyone recently dealt with Lambda or other AWS services being restricted after an account-compromise report? How long did restoration take, and what escalation path worked when the case appeared to be waiting for review?
1 Answer
It may be worth repeating every requested remediation step directly in the case, even if you already completed it, and documenting the exact date and time for each action. Automated security checks may be looking for recent credential changes, MFA updates, or other timestamps rather than relying on the original explanation. That is frustrating, but providing a concise checklist with the evidence and requesting a manual review may help move the case forward.

The bigger concern is the delay before the restriction was imposed. Reporting the compromise should have triggered an immediate review and containment, not an eight-day wait followed by instructions to repeat work that had already been done.