인피니언 8월20일부터
This page was machine-translated and may differ from the original. View original

Frequent AWS account hacking is causing widespread damage to developers.

Google 우선 소스Published2023.07.04 09:23
The rise of unauthorized use of IoT device cloud-linked accounts.
When discontinuing account use, it is necessary to protect your information, such as by deleting your membership.

There are cases where developers have suffered damages of hundreds of millions or even tens of millions of won due to hacking while using AWS-IoT accounts to connect IoT devices to the cloud, so caution is required.

Recently, a developer used a free AWS-IoT account to test cloud connectivity for IoT devices. This developer used a free AWS-IoT account with his company email account for simple testing and demonstration purposes.

After I left the company, I naturally stopped using the company email, but my AWS account was hacked and the server was used without permission, so AWS continued to send billing information to an email address that I no longer used after I left the company.

When the developer found out about this, millions of won had already been charged, and the password for the previously registered account had been changed, making it impossible to take security measures.

He said that he tried to notify AWS of this fact and take security measures, but AWS only responded that the owner had to access the account and take action.

However, if the victim wants to reset the password, he or she needs to receive a reset email to the email address registered to the account, but since he or she has already left the company, the email has been closed and he or she cannot receive or check the email.

Accordingly, the victim is said to be continuously contacting AWS Korea and the US headquarters to seek possible solutions.

It is known that this type of case is not limited to this developer, but there are cases of significant damage.

It is known that accidents frequently occur, especially among novice developers, when they are used for testing or training before developing official applications.

Hacking is indiscriminate, and while experienced developers are mindful of security measures like two-step authentication, novice developers often miss important security measures due to their unfamiliarity with English-language manuals.

In one case, a developer was charged hundreds of millions of won in usage fees and ended up in huge debt without even knowing it.

It is known that there is no specific solution. there is.

Most victims report the incident to the police or notify AWS of the damage and try to negotiate for a reduction in the usage fee, but it is very difficult to catch the perpetrator and it is also difficult to prove the damage through lawsuits, so in most cases, they are forced to pay the billed usage fee with tears in their eyes.

There are cases where some of the bills are reduced through negotiations with headquarters and Korean branches, but in the end, developers are still paying for costs they did not use.

Accordingly, affected developers are unanimously saying that if they create a free trial account for the AWS cloud, they need to be very careful about account security.

Experts say that although cloud companies say they are strengthening security, if your account is leaked, you can easily become prey to hackers. They advise that you should be careful to maintain double or triple security such as using two-step authentication and OPT passwords, and immediately delete unused accounts to eliminate the possibility of problems.
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.
배종인 기자
배종인 기자