Reporting abuse on AWS is the process by which customers, partners, and AWS personnel notify AWS of suspected misuse of AWS services, such as spam, fraud, malware distribution, denial-of-service attacks, or illegal content. This explainer describes how AWS handles reports, how to submit reports for different scenarios, how investigations typically work, and how to align with AWS policies and evidence requirements. The goal is to give teams a practical, evergreen framework for escalating abuse while preserving evidence, maintaining compliance, and communicating clearly with AWS and affected stakeholders.
What Constitutes Abuse on AWS
AWS abuse generally involves activity that violates AWS policies, laws, or the rights of others. Common examples include hosting malicious software, running spam or phishing campaigns, conducting fraud, launching denial-of-service attacks, scraping or harvesting data in violation of terms, exploiting vulnerabilities, or storing illegal content. Abuse can also include compromised accounts, insider threats, or misuse of AWS features to enable harmful behavior. AWS defines specific boundaries in the AWS Acceptable Use Policy and the AWS Customer Agreement, so checking those documents is the first step when determining whether an incident qualifies as abuse. Understanding these definitions helps teams judge whether an event is policy abuse, a potential security incident, or a legal matter requiring law enforcement involvement.
When to Report Abuse to AWS
You should report abuse to AWS when you observe or suspect misuse of AWS services that violates AWS policies or applicable laws. Examples include detecting malware hosted on AWS resources, identifying your account being used for spam or phishing, noticing signs of unauthorized access or compromised credentials, or discovering data that infringes intellectual property rights. If the activity also appears to be criminal—for example, fraud, extortion, or illegal hosting—consider involving law enforcement while also notifying AWS. Even if you are unsure whether an incident qualifies as abuse, it is often better to submit a report for assessment; AWS can triage and escalate internally as needed. Timely reporting helps limit lateral movement, reduces potential impact, and preserves evidence that may be useful in investigations or legal proceedings.
How to Report Abuse to AWS
Gather Internal Information First
Before contacting AWS, collect key internal details that speed up triage. These typically include the account ID, affected resources (instance IDs, IP addresses, domains, buckets), timestamps of suspicious events, and any relevant log excerpts or artifacts. Note the specific policy or law you believe was violated and the potential impact, such as data exposure, service disruption, or financial loss. Having this context reduces back-and-forth, clarifies severity, and helps AWS prioritize the report. Internally, you may also want to isolate affected systems, rotate credentials, and preserve logs to ensure evidence remains intact during the investigation.
Contact AWS Through Official Channels
Use the AWS Support plan that matches your needs to open a case, typically via the AWS Management Console or AWS Support API. Abuse and security issues are often handled by the AWS Abuse Team, which can escalate to specialized teams such as Trust & Safety or Security Response as required. For immediate, high-severity threats, such as active data exfiltration or infrastructure compromise, use your enterprise support contact or designated incident escalation process if available. If you are a business or enterprise customer, your technical account manager or account team can coordinate faster response and ensure proper alignment with AWS security workflows. AWS does not provide a public web form specifically for abuse, so support channels and, when warranted, law enforcement are the standard reporting paths.
Coordinate With Law Enforcement When Necessary
For incidents that may constitute a crime—such as fraud, extortion, harassment, or large-scale data theft—consider reporting to appropriate law enforcement authorities in parallel with notifying AWS. AWS can respond more efficiently when law enforcement provides legal requests like subpoenas or court orders, and in many regions AWS requires such legal instruments for certain disclosures of customer data. Contact local, national, or regional cybercrime units, and follow established processes for evidence submission. Coordination with legal and compliance teams early on can streamline requests, protect privileges, and align incident response with regulatory obligations.
What Happens After Submitting a Report
Intake and Triage
Upon receiving a report, AWS typically acknowledges receipt and assigns the case to the appropriate team, often the Abuse or Security Response groups. During triage, they assess severity, potential impact, and whether evidence is sufficient to proceed. They may request additional details, logs, or artifacts to complete their analysis. AWS aims to balance customer protection with fairness, and not every report results in immediate action; some may require more information or fall outside policy enforcement scope. Understanding this workflow helps set realistic expectations and reduces frustration during the waiting period.
Investigation and Remediation
If AWS proceeds, the investigation may include log analysis, network traffic examination, and coordination with other internal teams. When abuse is confirmed, common outcomes include mitigating the immediate harm, restricting the offending resources, or, in severe cases, terminating the involved account. Customers may receive updates about actions taken, but detailed evidence or legal restrictions can limit what AWS can share. Remediation can also involve repairing compromised systems, rotating keys, and implementing stronger controls to prevent recurrence. Close communication with AWS and your internal security group ensures a coordinated response and faster return to secure operations.
Best Practices for Reporting and Investigations
Plan Your Evidence and Reporting Process
Effective reporting starts with clear processes and evidence management. Maintain a log of when suspicious activity was first detected, how it was discovered, and who was notified. Capture relevant data—such as VPC flow logs, CloudTrail events, access logs, and packet captures—while preserving chain-of-custody practices if legal proceedings are possible. Document findings concisely and focus on factual, time-bound observations rather than speculation. Align internal stakeholders, including security, legal, and compliance, so that AWS receives a coherent narrative with appropriate context and desired outcomes.
Prevent Recurrence Through Controls and Policy Alignment
Beyond immediate remediation, strengthen controls to reduce future abuse risk. Use AWS Organizations and service control policies to enforce guardrails, enable AWS Config and Security Hub for continuous monitoring, and apply least-privilege IAM policies with regular credential rotation. Enable CloudTrail and VPC Flow Logs, centralize logs in a secure account, and implement automated alerts for anomalous behavior. Review and update your Acceptable Use Policy internally, train personnel on secure operations, and establish an incident response playbook that integrates AWS reporting steps. These practices make reporting abuse more efficient and demonstrate due diligence to auditors, customers, and regulators.
Comparison: Reporting Abuse vs. Internal Incident Handling
| Aspect | Reporting to AWS | Internal Incident Handling |
|---|---|---|
| Primary Goal | Request service remediation, policy enforcement, and potential account actions | Contain impact, preserve evidence, and coordinate response within your environment |
| Typical Audience | AWS Abuse Team, Trust & Safety, Security Response, or Support | Security, IT, legal, compliance, and executive leadership |
| Evidence Requirements | Concise facts, logs, timestamps, account IDs, and affected resources | Full forensic preservation, chain-of-custody, and detailed analysis |
| Outcome Examples | Resource restriction, account termination, legal requests to AWS | System isolation, credential rotation, legal proceedings, process improvements |
| Timing and Escalation | Guided by AWS intake and triage; may involve law enforcement coordination | Guided by internal incident response plan and SLAs |
Key Takeaways
- Abuse on AWS includes spam, fraud, malware, denial-of-service, illegal content, and compromised accounts; refer to the AWS Acceptable Use Policy for specifics.
- Report suspected abuse to AWS via your support plan, and engage law enforcement when the activity may be criminal.
- Provide account IDs, affected resources, timestamps, logs, and a clear description to speed up triage and investigation.
- After submission, AWS typically performs intake, triage, and, if warranted, investigates and remediates by mitigating and, if needed, restricting or terminating accounts.
- Combine reporting with strong internal controls, evidence preservation, policy alignment, and continuous monitoring to reduce recurrence and strengthen security posture.