Credential theft

DataDog AWS Access Keys Exposed in Breach

πŸ“… 2016-07-07 🏒 Amazon Web Services (AWS)
Primary Source β†—

Incident Details

On July 7-8, 2016, DataDog, a cloud monitoring and analytics platform, detected unauthorized access to its internal systems and discovered that AWS access keys had been exposed. DataDog immediately rotated all credentials and notified customers. Because DataDog agents run with IAM permissions inside customer AWS environments, the potential exposure of these keys raised concerns about downstream access to customer cloud infrastructure. DataDog stated it found no evidence that customer data was accessed. The company’s rapid response β€” detection and notification within approximately 24 hours β€” was noted as a positive example of breach response.

Technical Details

Initial Attack Vector
An attacker gained access to DataDog's internal systems and obtained AWS access keys, which could have been used to access customer AWS environments where the DataDog agent was installed
Vendor / Product
Amazon Web Services (AWS)

Timeline

  1. 2016-07-07 Breach occurred
  2. 2016-07-08 Publicly disclosed
  3. 2016-07-08 Customers notified