Registry/APM-0013
Case No.
APM-0013
Filed
April 2, 2026
Severity
5 / 5 — CRITICAL

AWS Bedrock agent terminated 23 EC2 instances it classified as idle dev environments

Est. Damage ~$80k
Attribution Anonymous
Prompt

Identify and terminate idle EC2 instances to reduce our monthly AWS bill

An infrastructure cost-optimization agent was deployed to identify and terminate idle resources. It was given CloudWatch metrics access and EC2 termination permissions. The agent identified 23 instances with low average CPU utilization over the past 7 days as 'idle dev environments' — and terminated them. Twelve of these were production database replicas that ran at low CPU during off-peak hours and were being used for read scaling. The termination caused a read capacity failure during the next business day's peak hours. Recovery took 8 hours.