CSIDB logo
Incident

Amazon Web Services

Incident posture

Attack window
2025
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-01 11:36

Linked entities

Victim
Amazon Web Services
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A series of major cloud infrastructure outages involving Amazon Web Services, along with Azure and Cloudflare, caused widespread global disruption to online services and customer-facing platforms. The incidents highlighted the systemic risk associated with cloud concentration, triggering cascading service failures across multiple SaaS organizations and affecting dependent businesses worldwide.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

0 techniques

Description

In 2025, Amazon Web Services (AWS) was among the cloud infrastructure providers affected by a series of major outages that ranked among the most significant cyber incidents of the year, according to Tokio Marine HCC International's sixth consecutive annual cyber incidents report. The outages, which also involved Microsoft Azure and Cloudflare, caused widespread global disruption and underscored the systemic risk posed by the concentration of cloud services. The cascading nature of the failures highlighted how disruptions at a small number of major providers can ripple outward, affecting countless downstream online services and customer-facing platforms. The inclusion of these outages in TMHCCI's top 10 list—selected for their operational disruption, financial impact, and broader implications for the global digital ecosystem—reflected concerns that cloud concentration has become a central driver of systemic cyber risk for organisations worldwide. TMHCCI noted that ransomware, technology supply-chain compromise, and cloud infrastructure concentration continue to be primary factors shaping the threat landscape, with the AWS, Azure, and Cloudflare outages cited as a clear illustration of that pattern.

The series of outages triggered cascading service failures across numerous software-as-a-service organisations, amplifying the impact far beyond the affected cloud providers themselves. While the report did not specify the precise dates, duration, or root causes of each individual outage, it characterised the collective events as having caused widespread global disruption affecting online services and customer-facing platforms used by organisations across multiple sectors. The report's authors emphasised the operational and financial consequences of such concentration, noting that even brief disruptions at major cloud providers can produce disproportionate downstream effects given the heavy reliance of modern digital infrastructure on a small number of hyperscale platforms. The outages involving AWS, Azure, and Cloudflare were presented alongside other major 2025 incidents—including ransomware attacks on Marks & Spencer and Jaguar Land Rover, a large-scale data breach exploiting compromised OAuth tokens in Salesforce and Drift environments, and an AI-orchestrated espionage campaign—as evidence of the evolving and broadening nature of cyber risk. No specific details regarding AWS's internal response actions, detection mechanisms, containment measures, or remediation steps were disclosed in the source material.

Sources

Sources available to members: 1 source.

CSIDB