2d ago · datadog-security-labs
Datadog Security Research observed a password spraying campaign from July 24 to August 23, 2026, targeting AWS root user accounts across more than 150 organizations. The attackers used specific Chrome and Firefox user agents and routed traffic through proxy infrastructure with IP addresses flagged as malicious or residential. A key indicator of this campaign is the use of valid root user email addresses, suggesting the attackers either had prior access to such lists or performed brute-force enumeration. No successful authentications were observed, and the motive remains unclear due to the lack of post-compromise activity.