The Containment Era is here. →Explore

Executive Summary

In October 2025, the Crimson Collective threat group executed a sophisticated attack targeting Amazon Web Services (AWS) cloud instances belonging to multiple organizations, most notably Red Hat. Utilizing exposed AWS credentials discovered via open-source reconnaissance tools, the attackers escalated their privileges by creating new IAM users with administrative rights. They then enumerated and accessed sensitive resources, including databases and storage volumes, exfiltrating approximately 570 GB of data from private GitLab repositories. The Crimson Collective followed up with extortion demands, leveraging AWS's internal and external email services to apply pressure on victims and collaborating with the Scattered Lapsus$ Hunters to intensify threats.

This incident underscores an escalating trend of cloud-focused threat actors exploiting credential exposures to breach critical infrastructure, bypass perimeter controls, and apply multifaceted extortion tactics. Organizations face increasing regulatory and business risk as attackers target cloud identity and API misconfigurations, requiring immediate attention to zero trust controls, egress restrictions, and anomaly detection in multi-cloud environments.

Why This Matters Now

Crimson Collective’s attack exemplifies the urgent threat posed by credential theft and privilege escalation in public cloud environments. As reliance on cloud services grows, attackers are targeting poorly governed IAM policies and API misuse—making it vital for businesses to rapidly harden access controls, enforce least privilege, and monitor for identity-based threats in real time.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

They exploited long-term AWS credentials and weak IAM policies, used TruffleHog to find secrets, escalated privileges, and created new admin users to access and exfiltrate sensitive data.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Zero Trust segmentation, network policy enforcement, east-west traffic protection, and egress controls—when applied in accordance with CNSF and validated security controls—would have blocked or rapidly detected many points in the attack, reducing attacker freedom to escalate, move laterally, or exfiltrate data. Centralized visibility and enforcement across cloud identities, network flows, and API actions could contain credential misuse, resource enumeration, and data theft.

Initial Compromise

Control: Multicloud Visibility & Control

Mitigation: Rapid detection of anomalous account/API usage from unfamiliar IPs or access patterns.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Limitation of privilege granting to only allowed identity groups and resources.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Lateral data access and service pivots are blocked or detected at segmentation/policy boundaries.

Command & Control

Control: Threat Detection & Anomaly Response

Mitigation: Real-time alerting on suspicious user/API activity and attempted persistent ingress or automation.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Outbound traffic and API-driven data transfers are filtered, restricted, or blocked if policy violations are detected.

Impact (Mitigations)

Inline detection of abnormal email patterns with incident response automation.

Impact at a Glance

Affected Business Functions

  • Data Management
  • Cloud Infrastructure
  • Customer Support
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: $5,000,000

Data Exposure

Approximately 570 GB of sensitive data, including 800 Customer Engagement Reports containing client infrastructure details, authentication tokens, and network configurations, were exfiltrated.

Recommended Actions

  • Enforce least-privilege IAM and routinely audit for unused or long-term access keys.
  • Implement Zero Trust Segmentation across cloud identities, networks, and workloads to restrict lateral movement and privilege escalation.
  • Deploy network-based egress filtering and east-west traffic inspection to block unauthorized data flows and exfiltration paths.
  • Leverage centralized visibility and anomaly detection for real-time monitoring of account, API, and resource behaviors.
  • Automate incident response playbooks that respond to signs of credential misuse, unusual resource provisioning, or sensitive data transfers.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image