Misconfigured object storage exposed 2.3 million broker settlement records for nine weeks
A single overly permissive bucket policy at a clearing-services vendor left trade confirmations readable to anonymous requests.
Daniel Okonjo
Cloud Security Correspondent • • 6 min read
A guardrail that was never on
The exposure was not the result of a sophisticated attack. It was the result of an automation script that had worked correctly for three years, running against an account where the organisation-wide public-access-block had been switched off during a migration in 2024 and never switched back.
Every control worked exactly as configured. The configuration was the incident.
Why the timeline is unclear
Server access logging was enabled, but with a 30-day lifecycle rule. By the time an external researcher reported the bucket, the first four weeks of request history had already aged out. The vendor's statement that there is no evidence of bulk download is therefore accurate but narrow.
Practical controls
- Enforce account-level public access blocking through service control policies, not local settings
- Retain object-level access logs for at least 180 days for any bucket holding regulated data
- Scan for wildcard principals in resource policies as part of continuous configuration review
- #Cloud
- #Data Exposure
- #Financial Services