upvote
When AWS suspects malicious usage in my experience they usually ask before shutting you down.

The company I work at got one of these emails from AWS. We had a bug which caused us to hit a 3rd party API much more than we should have, and the service provider reported us to AWS for attempted DDoS. AWS just asked us to give our side of the story. I'm sure that being a large (but not enterprise) customer gives us some leeway, but I've also heard similar things from hobbyists.

There are exceptions if you are a fairly new account, or if you operate in certain low reputation regions. Specifically I have heard regions in Africa tend to get the "shoot first ask questions later" treatment from AWS Support.

However, all of this was before 2026 (when AWS Support seems to have 100% turned over to AI). For all I know their actions might look completely different now.

reply
Did you know several service providers automatically suspend service based on a single unverified report from a pseudonymous account on AbuseIPDB? Make of that what you will.
reply
I think I still get a human (working for big enterprise company) but it's almost guaranteed that the first response will be useless.
reply
Ditto. My experience with AWS support has been generally disappointing.
reply
You just have to project life and death into your request and bobs your uncle!
reply