Is It Safe to Buy an AWS Account? Security Checklist for Buyers
Buying an existing Amazon Web Services account may appear to be a convenient way to access an established cloud environment, existing infrastructure, higher service quotas, billing history, or resources that are already configured. However, an AWS account is not simply a username and password. It can contain sensitive data, payment obligations, active cloud resources, identity permissions, contractual commitments, security vulnerabilities, and a complete history of previous activity. So, is it safe to buy an AWS account? The honest answer is that purchasing login credentials from an unknown seller is extremely risky. A legitimate transfer between businesses may be possible when it follows AWS requirements and includes complete legal, financial, administrative, and technical due diligence. However, buying an account informally through a marketplace, social media seller, or anonymous vendor can expose the buyer to account recovery fraud, unauthorized access, unexpected bills, security incidents, and account suspension. AWS states that account login credentials and private keys are for internal use and must not be sold, transferred, or sublicensed to another person or entity. At the same time, AWS publishes specific Account Assignment Requirements for legitimate transfers of an AWS account from one legal entity to another. These requirements include changing the root credentials, replacing account information, clearing outstanding balances, and accepting applicable AWS agreements. This guide explains the risks and provides a practical security checklist for anyone considering the acquisition of an existing AWS account. Buying Credentials Is Not the Same as Transferring an AWS Account The first step is understanding the difference between an informal account sale and an official account assignment. An informal sale usually involves a seller providing: A root email address A password An MFA code or device Access keys Billing information An account created using someone else’s identity This arrangement is dangerous because the seller may retain access to the original email, phone number, authentication device, API keys, support communications, or account recovery information. Changing the password alone does not necessarily give the buyer complete control. A legitimate account assignment is different. AWS has published requirements under which it consents to certain account assignments from one entity to another. Immediately after the transfer, the receiving entity must update the account with its own payment, billing, tax, and contact information. The account must not have an outstanding balance, and both parties may remain responsible for applicable fees and taxes incurred around the time of transfer. Certain support plans, discounts, AWS Artifact agreements, healthcare-data arrangements, resale relationships, and GovCloud accounts require additional handling. Therefore, buyers should avoid sellers who describe the transaction as simply “sending the login.” A real transfer should involve ownership documentation, administrative changes, financial verification, technical review, and compliance with current AWS terms. Why Buying an AWS Account Can Be Risky 1. The Seller May Recover the Account The most common risk is account recovery fraud. Even after you change the password, the seller may still control the original email inbox, registered phone number, backup MFA device, support case history, or corporate domain connected to the account. AWS account recovery may depend on access to the root user email address and registered phone number. AWS specifically recommends keeping both recovery channels current and accessible. A seller who retains control over either channel may be able to challenge your ownership later. This risk is especially high when the account was created using a temporary email address, rented phone number, fake identity, former employee’s email, or domain that the seller still owns. 2. Hidden Users and Credentials May Remain Active An AWS environment can contain many access methods beyond the root password. These may include: IAM users IAM roles Access keys Service-specific credentials SSH keys Federation providers IAM Identity Center users Cross-account roles Lambda environment secrets CI/CD deployment credentials Third-party integrations Access to encrypted backups Programmatic access from external applications A seller could create a hidden administrator, retain a cross-account role, or keep an access key that continues working after the root password is changed. AWS recommends regularly reviewing and removing unused users, roles, permissions, policies, and credentials. It also recommends temporary credentials, role-based access, MFA, and least-privilege permissions instead of relying heavily on long-term access keys. 3. You May Inherit Unpaid Bills An existing account can contain unpaid invoices, active resources, data-transfer charges, marketplace subscriptions, reserved capacity, support fees, savings commitments, or tax obligations. AWS requires that a transfer account have no outstanding balance at the time of assignment. It also states that the assignor and assignee can be responsible for fees, charges, and taxes incurred around the transfer, while the assignee is responsible for charges incurred afterward. Never rely only on a screenshot of the billing dashboard. The seller should provide access to invoices, cost reports, commitments, payment history, marketplace agreements, active subscriptions, and any open billing support cases. 4. Previous Abuse May Affect the Account A purchased AWS account may have been used for spam, phishing, malware distribution, unauthorized scanning, cryptocurrency mining, fraudulent transactions, or other prohibited activity. Even when the visible resources have been deleted, historical activity may remain in logs, support cases, abuse reports, external blocklists, IP reputation databases, or internal AWS risk systems. AWS may suspend access when it reasonably determines that account activity poses a security risk, could affect AWS or third-party systems, could create liability, appears fraudulent, violates the agreement, or involves unpaid charges. A seller offering a very old account, unusually high limits, promotional credits, unrestricted email capabilities, or “guaranteed no verification” access should be treated with extreme caution. 5. Existing Data May Create Legal Liability The account may contain customer information, backups, personal data, intellectual property, database snapshots, logs, medical information, authentication secrets, or regulated records. A buyer should not assume that ownership of the account automatically grants lawful ownership of all data inside it. The seller may not have the right to transfer customer information or third-party content. AWS specifically requires additional action when a transferred account contains protected health information. Applicable AWS Artifact agreements may also need to be terminated by the previous owner and
Is It Safe to Buy an AWS Account? Security Checklist for Buyers Read More »

