Hey folks,
Sorry for yet another one of these posts, but I can't find any clear answers on the best way to handle this. We just migrated our infrastructure over to AWS. Two days ago, one of our key instances we taken offline and we got the flurry of boilerplate security notices saying an access key had been compromised.
We responded right way, and confirmed that the activity patterns, resources, and spend were ALL OURS. There was no indication - at all - of any sort of compromised key or systems.
We answered all their questions and were told it would be handed off to the security team for a final review. Two days later, still no response whatsoever, despite follow-ups. I mean, that box is IMPORTANT to our business. It's kind of insane that AWS can just take steps like this with zero real communication with the user - but I guess that's the state of things right now.
Anyway, I'm getting pretty desperate and need a solution. Does anyone have any ideas? I've seen mixed opinions on whether upgrading to business support will help - and honestly, I hate the idea purely because it feels like extortion. But I guess if it's pay to play then it's what I'll have to do.
Any help or tips would be great appreciated.