Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Cyber Threats » ShinyHunters Allegedly Targets AWS Credentials with Amazon Bedrock Access

ShinyHunters Allegedly Targets AWS Credentials with Amazon Bedrock Access

By:
Last updated:August 27, 2026
Human Written
  • ShinyHunters reportedly wants AWS keys that can use Anthropic Claude models through Amazon Bedrock.

  • The claim has not been confirmed, and no victim list or working keys have surfaced.

  • Stolen AWS keys can create costs and wider risks when they carry access to other cloud services.

ShinyHunters Allegedly Targets AWS Credentials with Amazon Bedrock Access

ShinyHunters is reportedly looking to buy stolen AWS access keys with Amazon Bedrock access. Threat intelligence accounts on X (formerly Twitter) started reporting on August 26 that the group claims to buy AWS key pairs in the AKIA:SECRET format.

The post says the keys must have Bedrock access. It also says they must work with certain Claude models. However, the claim has not been confirmed by AWS, Anthropic, or an independent security firm. There is also no public proof that shows how many keys ShinyHunters has bought. No victim list has surfaced either.

That makes this an alleged criminal-market offer, not a confirmed breach. Still, the claim matters. A valid AWS key can give an attacker access to cloud services. A key with Bedrock access can also let someone run paid AI models. The risk can grow if the same key has wider rights.

What Stolen Keys Could Allow

Amazon Bedrock lets AWS customers use AI models from firms such as Anthropic. AWS says users can send requests to Claude through Bedrock. They need the right account setup and access rights first.

In plain terms, a stolen key could let an attacker use a company’s AWS account to run Claude. That could lead to a larger AWS bill. The real danger depends on the rights tied to the stolen key. For example, an identity may have access to storage, databases or other AWS services. The Bedrock permission alone does not give an attacker all of those rights.

AWS encourages its users to embrace the least privilege principle. This implies that each user and service must have just the necessary permissions. AWS also favors short-term credentials over long-term access keys. That matters because a long-term key can stay useful until the owner finds and disables it.

Claude Access Adds Another Incentive

The reported offer also shows why AI access could become useful to cybercrime groups. Amazon Bedrock supports several Anthropic Claude models. AWS lists Claude models from the Opus, Sonnet and Haiku families.

A stolen account with access to a costly model could have clear value. An attacker could use the account for its own work. The attacker could also try to sell the access to another criminal. This creates two possible gains. First, the attacker may avoid paying for the AI service. Second, the attacker may earn money by selling the stolen access.

The reported ShinyHunters offer appears to focus on keys that have already passed a test. That could make such keys more valuable than a random batch of leaked AWS credentials. However, no public evidence shows the test results. There is also no proof that any advertised keys still work.

ShinyHunters has Targeted AWS Credentials Before

This new allegation aligns with past activities associated with ShinyHunters. In 2024, experts discovered a massive operation that targeted cloud credentials and other secrets. According to reports, this activity could be attributed to ShinyHunters and another group called Nemesis.

The attackers scanned large numbers of internet-facing systems. They then searched exposed systems for AWS keys, database passwords, plus other confidential information. Researchers later discovered over 2TB of stolen data stored in an openly accessible AWS S3 bucket. The data included thousands of keys and other credentials.

The attackers had also tested stolen AWS keys for access to services such as IAM, S3, SES, and SNS. That history makes the latest claim worth watching. It does not, however, prove that ShinyHunters now holds AWS keys with Claude access.

Amazon Threat Intelligence linked North Korean group SAPPHIRE SLEET to supply-chain attacks on popular npm packages, including axios, debug, and chalk. By compromising maintainer accounts and pushing malicious updates, the group targeted downstream environments and cloud credentials through trusted channels.

AWS Customers should Check their Keys

The current claim remains unconfirmed, but AWS customers can still take action. Companies should review every active AWS access key. They should check when each key was last used and remove keys that no longer serve a purpose.

Security teams should also watch AWS logs for strange activity. A sudden rise in Bedrock requests could signal misuse. So could be used from an unusual location or a new network. Teams should also check whether old keys still exist in source code, build files or other exposed places.

Recent research found thousands of AWS keys that remained active after public exposure. That shows how long leaked keys can remain useful when owners fail to rotate or disable them.

Companies should replace exposed keys at once. Where possible, they should also use temporary credentials or IAM roles instead of long-term keys. For Bedrock, AWS lets administrators control which models users can call. This can help limit the damage from a stolen credential.

The ShinyHunters Claim Still Needs Proof

For now, the ShinyHunters report should remain an unconfirmed claim. There is no independent proof that the group has bought the advertised keys. No victim has been tied to the claim, and no working credentials have been made public.

But the risk behind the claim is real. AWS keys can open doors to cloud services. Bedrock access can also let attackers run paid AI models. If one stolen key provides both types of access, criminals could gain a useful cloud resource and a new way to make money.

For companies that use Amazon Bedrock, the lesson is simple: protect AWS keys as closely as any other high-value login. Even when a criminal claim proves false, exposed cloud keys still pose a serious risk.

Share this article

About the Author

Joahn G

Joahn G

Cyber Threat Journalist

Joahn is a cyber threat journalist dedicated to tracking the evolving landscape of digital risks. His reporting focuses on ransomware gangs, data breach incidents, and state-sponsored cyber operations. By analyzing threat actor motives and tactics, he provides timely intelligence that helps readers understand and anticipate the security challenges of tomorrow.

View all posts by Joahn G >
Comments (0)

No comments.