Thanks (upvoted.) This was the answer to my question, thank you. It is interesting though that per the original write-up at
https://news.ycombinator.com/item?id=8817299
"When I woke up the next morning, I had four emails from Amazon AWS and a missed phone call from Amazon AWS."
So Amazon clearly did have some very clear fraud signals.
I agree with you that my lack of knowledge isn't a guide, which is why I phrased it in the form of a question and asked HN. Your current comment is in fact the only actual (and perfectly sufficient) answer.
---
EDIT: regarding 4), out of curiosity, if they could legally and were allowed to tell programmatically if miner proceses were running and stop these for you, would you want them to? [preauthorize them to check and not allow it unless/until you lift this]. I would do so personally, as an added measure of security simply due to the incentive people have to steal my keys for this reason, and the fact that as a practical matter it does happen - as in the write-up, in which a .gitignore was ignored.
>so I installed the Figaro gem (a rails API key security gem), and trusted it to keep my API key off of git when I pushed. I opened the console and git push origin master to send the new version of my app, Shriek to Heroku.
>Figaro pops up on the command line as usual, but this time instead of saying “created application.yml, created .gitignore” It just said “created application.yml”.
It certainly sounds like something that could happen to me, or anyone, and does every day. but it sounds like you would not opt in to this? just curious.