That was my initial impression reading the OP as well, if your implementation is slow because you're using scans, well, it's because you're using scans. That said, I honestly don't know enough about the details regarding OP's implementation and why they couldn't refactor to properly Query the PK, but it sounds similar to how you'd authenticate reads on Firebase so maybe it's habits from a different platform kicking in. That said, Amplify allowing users to just get into GraphQL whether or not they actually need it might be a legitimate noob trap.
Eh their documentation is pretty clear about all this stuff and all the new directives released a couple years back (like the PK and index stuff) clearly guide people towards using indexed queries and not scans: https://docs.amplify.aws/cli/graphql/data-modeling/