incident summary
probable account takeover with immediate cloud persistence.
The demo case shows an administrative reset, MFA factor change, unfamiliar AWS login, and fresh access-key creation, plus a direct user denial message that strengthens the takeover hypothesis.