Skip to main content

There's a hole in my bucket

...or 'Why do people leave sensitive data in unprotected AWS S3 buckets?'

Liudmila Chernetska via Getty Images
This content was last reviewed on 05/03/2025

In his 'My cloud isn't a castle' blog, Andrew A discussed the general challenge of preventing leaks from misconfigured cloud services. Here we look at a specific service which we've been asked about: Amazon Web Services (AWS). 

It seems like every month there's a new announcement about an organisation suffering a data leak from an improperly-secured Amazon S3 bucket. Either the bucket was made public (exposing sensitive files to anyone on the Internet), or was left open to any authenticated AWS user (anyone can sign up to AWS to become an authenticated AWS user).

However, there's not much public discussion about why so many buckets end up exposed. A first thought might be 'someone forgot to lock down the access'. However, S3 buckets - by default - can only be accessed by the bucket owner. The owner must decide to make the bucket accessible, meaning data leaks are not due to users forgetting to lock them down. Something else must be going on....





Written by

Nigel C Platform Security Research