Dumbass security team ran some DNS scanning shit across our entire AWS infrastructure. Normally I would not care about this but they ran up ~$8k in our AWS account on Route 53 (
Gay AWS Feature ) for the past 3 months. I am pretty dialed on on our services in AWS which run in total about $5k a month. Which I think is pretty good overall and my team's overall spend per month is like ~$35k/month on various services.
I don't really know what they're doing but they apparently have been running similar costs per month in EVERY SINGLE ONE of our 50-60 AWS accounts. A lot more for the ones that support the commercial product. But they are being super faggots about cost attribution which is my primary concern. The bean counters are pretty sensitive to huge increases in team spend, at least my team's, and now security wont accept that any of these should be attributed to their team despite them being the ones doing it.
I imagine the bean counters are going to get on their case pretty bad when they realize InfoSec is running up at minimum $400k a month "scanning." It's all fallen into the various teams that own the AWS accounts because none of them actually belong to InfoSec so they inadvertently shielded themselves from scrutiny.