Just to be clear here, this means that for a time @awscloud support was able to read all of your S3 data. There is no mitigation; this role is mandatory.
If you had CloudTrail data events enabled, you can audit. If you didn’t, it may be time to declare a security incident.