The attack resembled a very aggressive, clever virus so the people behind it definitely had very advance knowledge of AWS.
They could enable regions we had disabled and recreate roles that were deleted in a matter of minutes, again MFA on, no keys.
AWS kept giving us conflicting instructions and refused to disable our account unless we stop the attack first.
We have been customers of AWS since 2014.
I believe during that time the Shared Responsibility Agreement did not exist, so AWS demanded we signed it now for them to even consider taking a look.
That's when I reached out to the Attorney General of my state who sent a letter to AWS and got things moving.
We were contacted by another team (two months later) in AWS that seemed much more knowledgeable and they gave us the scripts that eventually stopped the attack.
Our case is not that rare, if you do some research you'll fine plenty of stories like ours.
In what way did the attack resemble a very aggressive, clever virus?
Do you mean that it happened fast? How do you know it wasn't something simple like your credentials leaking?
On HN the usual way to quote is like I have done above.
I too react like the poster above you and would probably not quote that way except to ridicule. Hopefully there aren't many of these across my posts.
(As for an almost green account commenting on HN standards I have been here is some form or another since around 2009 I think, I just once in a while create a new account so it won't be trivially simple to doxx me.)
Extraordinary claims require extraordinary evidence.
Edit:
By the way, what do you mean by threat level here? And FWIW, here I could have used quotes without being rude.
Also: if you read that sentence again you'll probably find that it wasn't just the use of quotes but the sentence that as a whole that made it stand out as rude.
Suggesting it is an extraordinary claim, and would suggest an extraordinary threat to all AWS accounts. This seems very unlikely.