We had our AWS account hijacked three years ago. Someone had taken over our admin email by hijacking the DNS. They had hacked into our DNS account (with another provider) and changed the MX for our domain. Then they contacted customer support and convinced them to disable two factor authentication. Then they started to play with our account, starting and stopping servers.
Taking back the DNS took time. Meanwhile the hijackers were logged in, and could not be logged out by Amazon. This took more than a day. It took us two full days to get all back to normal.
The good thing is that they could not login to our servers. What they wanted is still not clear, and who did this - we saw some suspicious traffic from Russia, but that's all.