I have been seeing a lot of posts on Reddit and other forums of mostly students setting up an AWS account only for them to be hacked and account owner being stuck with a significant bill.
Most likely scenario is hackers are trying leaked username/password pairs from other breaches against AWS and gaining access to those accounts.
They then spin up EC2 instances in all sorts of regions on the compromised accounts
PSA set up MFA on your account if you haven't already.
Some examples:
https://www.reddit.com/r/aws/comments/rv3lm5/i_lost_55k_from...
https://www.reddit.com/r/aws/comments/rvbncu/account_hacked_...
https://www.reddit.com/r/aws/comments/qx8i02/got_hacked_and_...
https://www.reddit.com/r/aws/comments/rv4mnq/my_account_was_...
I don't even like the idea of any of this stuff. I want to run my own little raspberry pi server or whatever, it seems much more fun and startupish than aws, which appears to be all of the corporate stuff I left (AIMs etc). This is funny because I remember AWS being thought of as great for "just experimenting with stuff".