# Hijacking Amazon EventBridge for launching Cross-Account attacks

DevFeed: [Hijacking Amazon EventBridge for launching Cross-Account attacks](<https://devfeed.tech/articles/hijacking-amazon-eventbridge-for-launching-cross-account-attacks-15674.md>)

Original publisher: [Read original article](<https://developer.squareup.com/blog/hijacking-amazon-eventbridge-for-launching-cross-account-attacks>)

Author: Ramesh Ramani

Published: 2025-06-25T07:00:00Z

Content type: article

Language: en

Sources: [Square Corner Blog RSS Feed](<https://devfeed.tech/sources/square-corner-blog-rss-feed.md>)

Topics: [Amazon EventBridge](<https://devfeed.tech/topics/amazon-eventbridge.md>), [Security](<https://devfeed.tech/topics/security.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [Serverless](<https://devfeed.tech/topics/serverless.md>), [AWS IAM](<https://devfeed.tech/topics/aws-iam.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>)

Tags: [amazon-eventbridge](<https://devfeed.tech/tags/amazon-eventbridge.md>), [aws](<https://devfeed.tech/tags/aws.md>), [aws-eventbridge](<https://devfeed.tech/tags/aws-eventbridge.md>), [communication](<https://devfeed.tech/tags/communication.md>), [data-governance](<https://devfeed.tech/tags/data-governance.md>), [data-loss-prevention](<https://devfeed.tech/tags/data-loss-prevention.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [iam](<https://devfeed.tech/tags/iam.md>), [security](<https://devfeed.tech/tags/security.md>), [serverless](<https://devfeed.tech/tags/serverless.md>)

## AI overview

This article examines how misconfigured cross-account Amazon EventBridge flows can create inbound and outbound security risks. It describes possible event injection, triggering of vulnerable processing logic, and data exfiltration, and provides guidance for securing these configurations.

## Source excerpt

Securing the invisible paths: How cross-account event flows can become security blind spots