Massive AWS S3 Misconfiguration Exposes 8.4 Million Records Across 120 Organizations

2 min read

Massive AWS S3 Misconfiguration Exposes 8.4 Million Records Across 120 Organizations

–

A major misconfiguration in Amazon Web Services S3 buckets has exposed sensitive data belonging to more than 120 organizations, according to a report released by cloud security firm Wiz. The exposure, which affected companies across financial services, healthcare, and government sectors, underscores persistent challenges in cloud security posture management.

What Went Wrong

The root cause traces back to a default setting change in a popular infrastructure-as-code template widely distributed through open source repositories. The template, used by thousands of DevOps teams to provision AWS resources, contained a misconfigured access control list that granted public read access to newly created S3 buckets.

Wiz researchers discovered the issue during routine scanning and found that affected buckets contained a range of sensitive materials including customer databases, internal API keys, employee records, and in several cases, unencrypted personally identifiable information (PII).

The Scope of Exposure

Among the exposed data, researchers identified financial transaction records from three regional banks, patient intake forms from a healthcare network, and internal communications from a state government agency. In total, an estimated 8.4 million individual records were publicly accessible before the issue was remediated.

Cloud Misconfigurations Remain a Top Risk

Cloud misconfigurations have consistently ranked among the leading causes of data breaches. According to Gartner, through 2027, 99 percent of cloud security failures will be the customer’s fault, driven primarily by misconfiguration and inadequate access controls.

“The shared responsibility model means cloud providers secure the infrastructure, but customers must secure their own configurations,” said Ami Luttwak, CTO of Wiz. “Too many organizations still lack the tooling and processes to catch these errors before data is exposed.”

Remediation and Prevention

AWS has issued updated guidance urging customers to review their S3 bucket policies and enable the S3 Block Public Access feature at the account level. The company also announced plans to make Block Public Access the irrevocable default for new accounts starting in Q4 2026.

Best Practices for Cloud Security

Security experts recommend that organizations adopt a cloud security posture management (CSPM) platform to continuously monitor for misconfigurations. Additional measures include implementing least-privilege access policies, enabling logging and alerting on bucket policy changes, and conducting regular audits of infrastructure-as-code templates before deployment.

Organizations that rely on open source IaC templates should also verify configurations against their own security baselines rather than deploying them without review. The incident serves as a stark reminder that automation, while powerful, can amplify errors just as easily as it accelerates productivity.

As cloud adoption continues to accelerate, the gap between deployment speed and security oversight remains one of the most pressing challenges in enterprise cybersecurity.


David Hall

David Hall

David is the senior editor at TheCyberMag. He has a background in journalism and has worked with various media outlets, covering topics ranging from threat intelligence and data privacy to cybercrime and cloud security. When he is not writing, David enjoys reading, hiking, photography, and exploring new coffee shops.