Could an attacker create new users or administrators?¶
Yes. An attacker with sufficient cloud permissions may create new users, invite guests or assign administrator roles.
This can give them additional access that remains even if the original account is secured.
What this means in practice¶
An attacker may create a new account, promote an existing account, add an external guest or grant an application administrative permissions.
They may choose names that resemble legitimate users, support accounts or automated services. The account may remain unused until the attacker returns later.
In an organisation, compare these records with approved onboarding, help-desk requests and change-management records. A legitimate administrator may have created the account during routine work.
Where compromise is active, review all new or changed identities, not just the original account. Check recovery details, trusted devices, service accounts, API keys and delegated applications as well.
What this does not show on its own¶
The dangerous assumption is that resetting the compromised user’s password removes the attacker from the environment.
What to do next¶
Look for user-creation events, invitations, role assignments, group membership changes and administrator-consent records.
Identify which account performed the action, which session or application it used, when the change occurred and what permissions were granted.
Do not assume that the creator personally controlled the new account later. The attacker may have used a compromised administrator, an application or automation.
Preserve the audit trail before removing accounts where operationally possible. Deletion may alter the evidence and make later reconstruction harder.
Key takeaway
An attacker may create alternative identities or elevate permissions, so review all user, guest, role and administrator changes when investigating cloud compromise.