Datadog Security Research saw a password-spraying campaign against AWS root user accounts at more than 150 organizations from July 24 to August 23, 2026. Most targets saw only a couple of failed logins, but the traffic came through proxies and mixed Chrome and Firefox user agents, which points to an effort to stay quiet rather than blast through accounts.
The campaign had to know, or guess, the email address tied to each root account before AWS would even register the login attempt. That matters because the root user can change billing, account settings, and recovery paths that no other identity can touch, so a successful hit would land on the control plane, not just on one user session.
For organizations that still keep persistent root access in play, the account name itself is part of the exposure: once it is known, low-volume spraying can directly probe the highest-privilege identity. Datadog says it has not seen a successful login, so the remaining question is who can still spot and separate this kind of reconnaissance from ordinary authentication noise.