Credential theft
DataDog AWS Access Keys Exposed in Breach
Primary Source βIncident Details
On July 7-8, 2016, DataDog, a cloud monitoring and analytics platform, detected unauthorized access to its internal systems and discovered that AWS access keys had been exposed. DataDog immediately rotated all credentials and notified customers. Because DataDog agents run with IAM permissions inside customer AWS environments, the potential exposure of these keys raised concerns about downstream access to customer cloud infrastructure. DataDog stated it found no evidence that customer data was accessed. The company’s rapid response β detection and notification within approximately 24 hours β was noted as a positive example of breach response.
Technical Details
- Initial Attack Vector
- An attacker gained access to DataDog's internal systems and obtained AWS access keys, which could have been used to access customer AWS environments where the DataDog agent was installed
- Vendor / Product
- Amazon Web Services (AWS)
Timeline
- 2016-07-07 Breach occurred
- 2016-07-08 Publicly disclosed
- 2016-07-08 Customers notified