A threat actor bypassed EDR, sat quietly in a mid-sized company's AWS environment for more than 30 days, and slowly encrypted data on its way to storage — poisoning every backup along the way. Elastio and the AWS Security Incident Response team walk through what happened, why the customer's tooling never saw it, and what readiness has to look like now that AI has compressed the attack timeline from weeks to hours.
The session opens with a real engagement. A successful mid-sized billing provider running on AWS — a capable IT team with best-of-breed tooling — was breached at the firewall and then bypassed EDR entirely. The attacker dwelled for over 30 days, mapped the environment, and placed a decryption key in memory on a key server. From that point on, every read was silently decrypted for users and every write was silently encrypted on the way back to storage. For roughly 11 days, the company's own backup jobs were faithfully capturing poisoned data. Because the encryption was slow, striped, and fileless, entropy detectors, signature scanners, and malware detection never fired.
When the attacker pulled the key, the business went offline overnight. AWS Security Incident Response engaged alongside Elastio and AWS partner JetSweep, used data-layer telemetry to pinpoint exactly when the encryption began, and identified the last known clean copy. The company recovered — but it lost six days of downtime and roughly ten days of data. It was survivable rather than an extinction-level event, and the difference came down to how quickly the team could answer one question: which copy can we actually trust?
Dean Lawrence then covers what AI has changed and what it has not. Attacker objectives are the same; the speed is not. The Hugging Face incident, where an autonomous agent ran an intrusion end to end, marks a shift from the exploit itself to the reasoning — the decision loop now runs faster than any human operator. The cyber kill chain that threat models were built around is executing in hours instead of weeks, which leaves defenders less time to detect, decide, contain, and recover. The uncomfortable takeaway is that speed doesn't reward clever tooling. It rewards hygiene: protect identity first, scope permissions, reduce blast radius, and rehearse the response chain end to end, because AI reaches a door that's slightly ajar much faster than anyone used to.
The session closes on the gap that decides outcomes. Perimeter, network, identity, and endpoint tools tell you where a threat is moving, but not what has happened to your data. Restoring is not the same as recovering: if the copy you restore is corrupt, you are back at zero. Elastio inspects at the data layer, detects encryption behavior at its earliest stage — including the slow and zero-day activity other tools miss — and feeds that telemetry into AWS Security Hub, where AWS Security Incident Response can act on it. In the case discussed, that signal would have surfaced the attack while it was still unfolding.
Security leaders, incident response and SOC teams, cloud architects, and infrastructure and resilience owners responsible for detecting ransomware and proving that recovery data on AWS is clean.