TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Ask HN: AWS continues to charge me even though a hacker uses my account

8 点作者 unknownsavage大约 6 年前
Around 8 months ago I lost control of my AWS account after a prolonged social-engineering campaign against my account. Although it was a nightmare, thanks to a robust offsite backup solution we were able to quickly migrate to google cloud (which has Advanced Account Protection, a godsend for anyone in my position).<p>Strangely enough, even after several attempts I was never able to recover my hacked AWS account (from my support calls it seems like the attacker changed the email, name, address) and have never been able to authenticate against it.<p>However the one thing that was never changed is my credit-card. I have offered AWS support several times to give them my credit number and ask them to unlink it from the account, but they refuse to do so without me being authenticated.<p>I don&#x27;t want to get on Amazon&#x27;s bad side, but with no options left I have been resorting to charge-backs on the credit card. Thankfully my bank has been siding with me, and each month I have been winning them -- but next month the new bill comes and I forced to repeat the process.<p>Not wanting to get a bad reputation with my bank or Amazon, I just asked my bank to send me a new card. But amazingly (?!!!) the next month the bill from AWS still came on the new card.<p>It&#x27;s now been 8 months, and I&#x27;m sick of the absurdity of the situation. Is there anything I can do?

6 条评论

3into10power5大约 6 年前
There is a shitty think called &quot;Card refresh&quot;. Big companies can have deals with Credit card companies, because, at the end of the day, both of them need your money.<p>Lets say, you gave your card automatic monthly billing to company &#x27;X&#x27;. You would normally expect that when card expires, it won&#x27;t be billed anymore and they will ask you for new card details. The reality is company &#x27;X&#x27; goes to credit card company and tells them &quot;We have these card details with us. Everything except expiry date is same. So you can conclude that we legitimately obtained the card details. Can you give us the new card details. We will update the account accordingly. It is even useful to the customer as he will be (cough cough) inconvenienced.&quot;<p>I think something similar happened in your case. Source: I implemented this in a big e-commerce company(Not AMZN).
评论 #19583526 未加载
LinuxBender大约 6 年前
Go to your bank and dispute the charges. Get a new card (again), and specifically ask for a new card number because yours was compromised (for all intents and purposes).
hombre_fatal大约 6 年前
It&#x27;s absolutely absurd that you cannot authenticate by proving that you&#x27;re the one paying the account&#x27;s bill before and after the credentials were changed.<p>This is a good reminder of how unprepared even large corporations like Amazon are for the reality of social engineering attacks.
codegeek大约 6 年前
Can you not ask the bank to issue a new card with a NEW NUMBER ? Am I missing something ?
评论 #19589635 未加载
crooked-v大约 6 年前
At this point, you may have to get a lawyer to write them a nastygram about it.
ltmi600大约 6 年前
Cancel your AWS account and create a new one.