Dear AWS Support Team,
We have taken immediate action to secure the affected AWS account.
The affected IAM user's console access has been disabled and the compromised access key has been deactivated. We have created a replacement access key and are updating the associated staging application to use the new credentials.
We are also reviewing AWS CloudTrail logs for unauthorized activity and have reviewed the account for unexpected IAM resources and AWS service usage, including billing activity.
We will delete the compromised access key after confirming that the application is fully operating with the replacement credentials.
We will continue monitoring the account and will inform you immediately if we identify any unauthorized activity or unexpected usage.
Regards,
Ravi
