{"slug": "hootsuite-leaked-aws-keys", "title": "Hootsuite Leaked AWS Keys", "summary": "A report from Lunar Cyber reveals that hootsuite.com suffered a significant credential exposure event, with over 346,000 total events, including 346,082 client accounts and 400 employee accounts compromised. Approximately 89% of events are historical data breaches, while 10.9% are active infostealer logs featuring malware families such as LummaC2, Rhadamanthys, and Acreed. The data suggests credential stuffing attacks, with 99.9% correlation with combolist sources, posing high-priority risks to Hootsuite's login and billing endpoints.", "body_md": "# hootsuite.com Domain Breach Exposure Report\n\n## Risk Score\n\nMassive event volume or critical assets compromised.\n\n## AI Findings Summary\n\nThe telemetry indicates a significant exposure event impacting hootsuite.com, with over 346,000 total events recorded during the reporting period. The majority of these events, approximately 89%, are classified as historical data breaches, while 10.9% are active infostealer logs. A substantial number of client accounts (346,082) and employee accounts (400) are affected. Malware families such as LummaC2, Rhadamanthys, and Acreed are prominently featured in the infostealer logs. The data suggests a strong correlation with \"Combolist sources\" (99.9%) within leak repositories, indicating credential stuffing or similar attacks leveraging previously compromised credentials. The high volume of historical data breaches and active infostealer logs, coupled with the targeting of hootsuite.com login and billing endpoints, suggests a high-priority risk. The prevalence of infostealer malware targeting Windows 11 and Windows 10 operating systems, with a notable presence in India and the United States, points to a broad attack surface. Remediation efforts should focus on immediate credential rotation for affected employees and clients, enhanced monitoring for suspicious login activity, and a review of authentication mechanisms to mitigate credential stuffing and infostealer threats.\n\n## Total Events\n\n## Employee Affected Events\n\n## Client Affected Events\n\n## Check your company's\n\nexposed credentials[Create Your Free Account](https://app.lunarcyber.com/signup)\n\n## 12-Month Events Timeline\n\nEvent volume by breach date, employee VS client\n\n## Infostealers VS Data Breaches\n\nLive stealer logs VS data breaches\n\n**37,935** events\n\n**308,547** events\n\n**400 compromised employee** accounts pose an infrastructure risk, while **346,082 leaked client** credentials create regulatory liability.\n\n## Antivirus Distribution\n\nSecurity Tools on Infected Endpoints\n\n## Malware Families Distribution\n\nDistribution of Active Stealer Strains\n\n## Top Login URLs\n\nTop exposed services found in the event results\n\n## Infostealer By Geography\n\nShows the distribution of Infostealer-related credential exposure events across different geographic regions. The location is determined by analyzing the metadata of the infected machines associated with each event.\n\n### Country Breakdown\n\n## Services Classification Distribution\n\nBlast radius - closer to core = more critical infrastructure, size = credential volume\n\n## Operating System Distribution\n\nDistribution of compromised endpoint builds\n\n## Leak Repository Classification\n\nWhere the exposed records currently reside\n\nDisclaimer: This report includes AI-generated content. AI can make mistakes, so verify important findings independently before taking action.", "url": "https://wpnews.pro/news/hootsuite-leaked-aws-keys", "canonical_source": "https://lunarcyber.com/domain-exposure/hootsuite.com", "published_at": "2026-08-22 14:15:49+00:00", "updated_at": "2026-08-22 14:44:01.752072+00:00", "lang": "en", "topics": ["ai-ethics"], "entities": ["Hootsuite", "Lunar Cyber", "LummaC2", "Rhadamanthys", "Acreed"], "alternates": {"html": "https://wpnews.pro/news/hootsuite-leaked-aws-keys", "markdown": "https://wpnews.pro/news/hootsuite-leaked-aws-keys.md", "text": "https://wpnews.pro/news/hootsuite-leaked-aws-keys.txt", "jsonld": "https://wpnews.pro/news/hootsuite-leaked-aws-keys.jsonld"}}