cd /news/ai-ethics/hootsuite-leaked-aws-keys · home topics ai-ethics article
[ARTICLE · art-107119] src=lunarcyber.com ↗ pub= topic=ai-ethics verified=true sentiment=↓ negative

Hootsuite Leaked AWS Keys

A report from Lunar Cyber reveals that hootsuite.com suffered a significant credential exposure event, with over 346,000 total events, including 346,082 client accounts and 400 employee accounts compromised. Approximately 89% of events are historical data breaches, while 10.9% are active infostealer logs featuring malware families such as LummaC2, Rhadamanthys, and Acreed. The data suggests credential stuffing attacks, with 99.9% correlation with combolist sources, posing high-priority risks to Hootsuite's login and billing endpoints.

read2 min views1 publishedAug 22, 2026
Hootsuite Leaked AWS Keys
Image: source

Risk Score #

Massive event volume or critical assets compromised.

AI Findings Summary #

The telemetry indicates a significant exposure event impacting hootsuite.com, with over 346,000 total events recorded during the reporting period. The majority of these events, approximately 89%, are classified as historical data breaches, while 10.9% are active infostealer logs. A substantial number of client accounts (346,082) and employee accounts (400) are affected. Malware families such as LummaC2, Rhadamanthys, and Acreed are prominently featured in the infostealer logs. The data suggests a strong correlation with "Combolist sources" (99.9%) within leak repositories, indicating credential stuffing or similar attacks leveraging previously compromised credentials. The high volume of historical data breaches and active infostealer logs, coupled with the targeting of hootsuite.com login and billing endpoints, suggests a high-priority risk. The prevalence of infostealer malware targeting Windows 11 and Windows 10 operating systems, with a notable presence in India and the United States, points to a broad attack surface. Remediation efforts should focus on immediate credential rotation for affected employees and clients, enhanced monitoring for suspicious login activity, and a review of authentication mechanisms to mitigate credential stuffing and infostealer threats.

Total Events #

Employee Affected Events #

Client Affected Events #

Check your company's #

exposed credentialsCreate Your Free Account

12-Month Events Timeline #

Event volume by breach date, employee VS client

Infostealers VS Data Breaches #

Live stealer logs VS data breaches

37,935 events

308,547 events

400 compromised employee accounts pose an infrastructure risk, while 346,082 leaked client credentials create regulatory liability.

Antivirus Distribution #

Security Tools on Infected Endpoints

Malware Families Distribution #

Distribution of Active Stealer Strains

Top Login URLs #

Top exposed services found in the event results

Infostealer By Geography #

Shows the distribution of Infostealer-related credential exposure events across different geographic regions. The location is determined by analyzing the metadata of the infected machines associated with each event.

Country Breakdown

Services Classification Distribution #

Blast radius - closer to core = more critical infrastructure, size = credential volume

Operating System Distribution #

Distribution of compromised endpoint builds

Leak Repository Classification #

Where the exposed records currently reside

Disclaimer: This report includes AI-generated content. AI can make mistakes, so verify important findings independently before taking action.

── more in #ai-ethics 4 stories · sorted by recency
── more on @hootsuite 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/hootsuite-leaked-aws…] indexed:0 read:2min 2026-08-22 ·