CIO Brief: Cloud-Native Ransomware Doesn't Need Malware
Retrospective: this article looks back at events from January 2025, written in 2026 with the benefit of hindsight.
The short version: In early 2025, attackers used stolen AWS keys to lock companies' cloud storage files with encryption keys only the attackers had — using a legitimate AWS feature. No malicious software was needed. Companies without backups or file version history faced paying a ransom.
Why this is different from traditional ransomware
Traditional ransomware runs malicious programs on computers. Cloud-native ransomware simply uses stolen credentials to call normal cloud functions — encrypt, overwrite, delete. Antivirus can't stop it because there's no malware.
The business impact
- Data loss or ransom payment if files can't be restored.
- Fast timelines — attackers set files to be deleted within days.
- Cloud provider can't help recover data encrypted with keys it never had.
Questions to ask your team
- Can we restore our most important cloud storage data if it's overwritten or deleted?
- Do we keep versions and backups in a separate, protected account?
- Do we block cloud features we don't use, like customer-provided encryption?
- Do we still use long-lived cloud access keys?
What good looks like
Versioning and immutable backups for critical data, unused risky features blocked, short-lived credentials only, and monitoring for mass changes to stored data.
The decision
Ask your team to demonstrate restoring a critical S3 dataset from backup. If they can't, that's the priority — ahead of any new security tool.
- Codefinger (Jan 2025): Ransomware That Encrypts S3 Buckets With AWS's Own SSE-C Incident Teardowns
- How to Block SSE-C Usage and Protect S3 With Versioning and Object Lock How-To & Hardening
- Detecting S3 Ransomware SSE-C: CloudTrail, GuardDuty and Athena Queries Detection & Response