Yeah, that's not even bad... What AWS doesn't tell you, is elastic beanstalk creates new security groups and what not. So if (like me) you manage 12 Apps and you try to destroy one environment, the environment won't delete.
Apparently, they all try to create the same named security group (as well as other components). This happens even if you change the security groups after launch. So it'll error out and be unable to delete the rest of the components. Leaving a "ghost" environment.
That's just one of my many, many frustrations with it. I'm considering moving back to digitial ocean (where I was). However, the billing breakdown is nice to share with clients