They did a good thing, title feels slightly misguiding. Could they have figured it out based on API access locations being random?
No intention to misguide. I think it's completely accurate. They downloaded my app, inspected it, found AWS credentials and emailed me as a result.