TL;DR: TruffleNet used stolen AWS credentials, valid API calls, and trusted services like SES to run business email compromise at scale, showing how static cloud identities can be abused without malware or a zero-day, according to Defakto Security. The real failure is architectural: long-lived credentials still outlast the runtime context they were meant to represent.
Editorial analysis by NHI Mgmt Group, based on content published by Defakto Security: “TruffleNet and Cloud Abuse at Scale: An Identity Architecture Failure”.
Key questions
Q: What breaks when workloads still rely on static credentials for service-to-service access?
A: Static credentials break down when workloads are ephemeral, distributed across multiple environments, or expected to authenticate without preconfigured secrets.
Q: Why does long lived AWS key abuse create such high persistence risk in cloud environments?
A: Long lived access keys give attackers an authenticated foothold that looks legitimate at the API layer.
Q: How do security teams know if cloud identity controls are failing?
A: The clearest sign is when a stolen credential can be validated, reused, and operationalised from infrastructure that has no relationship to the original workload.
Practitioner guidance
- Eliminate reusable cloud access keys Inventory long-lived AWS access keys, service account secrets and similar static cloud credentials, then define which workloads still depend on bearer-style access and where runtime-issued identity can replace them.
- Constrain trusted service permissions Review permissions on services such as email delivery, signing and notification paths so a single compromised key cannot both authenticate and abuse a trust-bearing service.
- Bind identity to workload context Move toward ephemeral identities that are tied to the specific workload, pipeline or service instance so stolen credentials cannot be replayed independently of the runtime that requested them.
Bottom line: TruffleNet is a reminder that static cloud credentials are not just secrets to protect. They are durable trust objects that can be replayed outside the workload that created them.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Static cloud credentials are a runtime liability, not just a lifecycle problem. TruffleNet shows that a long-lived access key is not merely a secret to be rotated. It is a portable trust grant that can be stolen, validated and reused from attacker infrastructure. The practical conclusion is that cloud identity must be treated as an execution-time control, not a stored asset.
A few things that frame the scale:
- 69% of organisations still authenticate machine identities with long-lived API keys, according to the 2026 State of AI Agent Identity Security Report.
A question worth separating out:
Q: Should organisations rely on rotation or move to ephemeral identity for cloud access?
A: Rotation still helps for legacy coverage, but it should not be treated as a fix for static cloud identity. When a key remains usable between rotations, the compromise window is still large enough for abuse. Ephemeral runtime identity removes the durable secret instead of merely shortening its lifespan.
👉 Read our full editorial: TruffleNet shows static cloud credentials still fail at scale