AWSCIO BriefingsRetrospectives

CIO Brief: Cloud-Native Ransomware Doesn't Need Malware

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from January 2025, written in 2026 with the benefit of hindsight.

The short version: In early 2025, attackers used stolen AWS keys to lock companies' cloud storage files with encryption keys only the attackers had — using a legitimate AWS feature. No malicious software was needed. Companies without backups or file version history faced paying a ransom.

Why this is different from traditional ransomware

Traditional ransomware runs malicious programs on computers. Cloud-native ransomware simply uses stolen credentials to call normal cloud functions — encrypt, overwrite, delete. Antivirus can't stop it because there's no malware.

The business impact

  • Data loss or ransom payment if files can't be restored.
  • Fast timelines — attackers set files to be deleted within days.
  • Cloud provider can't help recover data encrypted with keys it never had.

Questions to ask your team

  • Can we restore our most important cloud storage data if it's overwritten or deleted?
  • Do we keep versions and backups in a separate, protected account?
  • Do we block cloud features we don't use, like customer-provided encryption?
  • Do we still use long-lived cloud access keys?

What good looks like

Versioning and immutable backups for critical data, unused risky features blocked, short-lived credentials only, and monitoring for mass changes to stored data.

The decision

Ask your team to demonstrate restoring a critical S3 dataset from backup. If they can't, that's the priority — ahead of any new security tool.

codefinger ransomware impactCodefinger SSE-C ransomware2025

More on this story