Cloud credential theft → account takeover
SSRF to the metadata endpoint steals IAM credentials. Those credentials may allow the attacker to access all S3 data, invoke Lambda functions, spin up EC2 instances, or access RDS databases — full cloud account compromise. Capital One impact: 100M records.