---
title: Amazon Battles Leaky S3 Buckets with a New Security Tool
description: Amazon Battles Leaky S3 Buckets with a New Security Tool
image: https://businessinsights.bitdefender.com/hubfs/buckets.jpeg
---

[![](https://businessinsights.bitdefender.com/hubfs/2021/09/logo-white.svg)](https://businessinsights.bitdefender.com/?hsLang=en-us)

[![CONTACT AN EXPERT](https://hubspot-no-cache-eu1-prod.s3.amazonaws.com/cta/default/341979/1d8885e9-1179-49b1-a5ec-9c75f5f670dd.png)](https://hubspot-cta-redirect-eu1-prod.s3.amazonaws.com/cta/redirect/341979/1d8885e9-1179-49b1-a5ec-9c75f5f670dd)

- [For Home](https://www.bitdefender.com/solutions/)
- [For Business](https://www.bitdefender.com/business/)
- [Resources](https://www.bitdefender.com/business/resource-library.html)
- [Webinars](https://www.bitdefender.com/business/webinars.html)

# [BUSINESS INSIGHTS](https://businessinsights.bitdefender.com/?hsLang=en-us)

 By [**Graham Cluley**](https://businessinsights.bitdefender.com/author/graham-cluley) / Dec 07, 2019

# Amazon Battles Leaky S3 Buckets with a New Security Tool

Share this [![Share on email](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/email-color.png)](mailto:?subject=Check%20out%20https://businessinsights.bitdefender.com/amazon-battles-leaky-s3-buckets-with-a-new-security-tool&utm_medium=social&utm_source=email%20&body=Check%20out%20https://businessinsights.bitdefender.com/amazon-battles-leaky-s3-buckets-with-a-new-security-tool&utm_medium=social&utm_source=email) [![Share on twitter](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/twitter-color.png)](https://twitter.com/intent/tweet?original_referer=https://businessinsights.bitdefender.com/amazon-battles-leaky-s3-buckets-with-a-new-security-tool&utm_medium=social&utm_source=twitter&url=https://businessinsights.bitdefender.com/amazon-battles-leaky-s3-buckets-with-a-new-security-tool&utm_medium=social&utm_source=twitter&source=tweetbutton&text=) [![Share on linkedin](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/linkedin-color.png)](http://www.linkedin.com/shareArticle?mini=true&url=https://businessinsights.bitdefender.com/amazon-battles-leaky-s3-buckets-with-a-new-security-tool&utm_medium=social&utm_source=linkedin) [![Share on facebook](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/facebook-color.png)](http://www.facebook.com/share.php?u=https://businessinsights.bitdefender.com/amazon-battles-leaky-s3-buckets-with-a-new-security-tool&utm_medium=social&utm_source=facebook)

Anyone who has been following security trends in recent years cannot fail to have noticed the preponderance of data breaches which have stemmed from unsecured Amazon S3 buckets.

Many well-known organisations, including [FedEx](http://www.zdnet.com/article/unsecured-server-exposes-fedex-customer-records/), [Capital One bank](https://www.prnewswire.com/news-releases/capital-one-announces-data-security-incident-300892738.html), [Verizon](https://www.scmagazine.com/verizon-data-found-on-open-aws-s3-server/article/695165/), and even [US defense contractors](https://www.grahamcluley.com/us-defense-contractor-secures-amazon-s3-bucket-leaving-sensitive-data-publicly-exposed/), have left confidential and sensitive data publicly exposed by not having properly configured the security of their cloud-based storage servers.

In fact, the problem became so bad that some security researchers have even been known to leave ["friendly warnings"](https://www.bbc.co.uk/news/technology-42839462) on exposed servers when they came across them, advising their owners to review their settings.

![friendly-warning](https://businessinsights.bitdefender.com/hs-fs/hubfs/friendly-warning.jpeg?width=1400&name=friendly-warning.jpeg)

In late 2017, Amazon Web Services (AWS) [announced](https://aws.amazon.com/blogs/aws/new-amazon-s3-encryption-security-features/) that it was introducing "bright orange pill" warnings onto server administrators' dashboards warning them if buckets had been configured to be publicly accessible.

![orange-pill](https://businessinsights.bitdefender.com/hs-fs/hubfs/orange-pill.jpeg?width=700&name=orange-pill.jpeg)

That was a positive step, but the continuing revelations of privacy-busting data breaches from unsecured storage servers meant that more still needed to be done.

This week Amazon [announced](https://aws.amazon.com/about-aws/whats-new/2019/12/introducing-access-analyzer-for-amazon-s3-to-review-access-policies/) its newest feature - the AWS Identity & Access Management Access Analyzer - that, amongst other things, monitors S3 bucket access policies and provides alerts if you have a cloud-storage bucket that is configured to allow access to anyone on the internet or that is shared with other AWS accounts.

![analyzer](https://businessinsights.bitdefender.com/hs-fs/hubfs/analyzer.jpeg?width=700&name=analyzer.jpeg)

In short, the new feature is supposed to help avoid accidental misconfigurations that could result in sensitive data being exposed, and subsequently damaging a company's brand and even - potentially - putting its customers at risk.

If the Access Analyzer tool discovers that a bucket is misconfigured you can respond to the alert by making a single click to ["Block All Public Access,"](https://docs.aws.amazon.com/AmazonS3/latest/dev/access-control-block-public-access.html) and then use the tool's report to understand the nature of the problem so you can fully address it.

Of course, it's perfectly possible that there is data on your AWS cloud servers which **is** supposed to be shared on the general internet (webpages, for instance), and these can be marked as intentionally public to avoid repeat warnings.

Aside from Amazon S3 buckets, IAM Access Analyzer can also analyse the permissions granted using policies for your AWS KMS keys, Amazon SQS queues, AWS IAM roles, and AWS Lambda functions.

As ever with security, you would be wise to follow the principle of least privilege, granting only the permissions required to perform a particular task and no more.

To enable the feature, administrators should visit their IAM console and enable the AWS Identity and Access Management (IAM) Access Analyzer. It will then appear in the S3 Management Console.

It's clearly a good thing that Amazon has developed an additional tool to help protect companies from leaking data through servers they have configured poorly.  But an alert is only half the battle - we still need companies to understand the severity of the issue and tackle it promptly when it is brought to their attention.

### Explore More Topics

- [Enterprise Security (743)](https://businessinsights.bitdefender.com/topic/enterprise-security)
- [Threat Research (201)](https://businessinsights.bitdefender.com/topic/threat-research)
- [Cloud Security (174)](https://businessinsights.bitdefender.com/topic/cloud-security)
- [SMB Security (170)](https://businessinsights.bitdefender.com/topic/smb-security)
- [Ransomware (166)](https://businessinsights.bitdefender.com/topic/ransomware)
- [Privacy and Data Protection (137)](https://businessinsights.bitdefender.com/topic/privacy-and-data-protection)
- [Cybersecurity Awareness (134)](https://businessinsights.bitdefender.com/topic/cybersecurity-awareness)
- [Endpoint Protection & Management (126)](https://businessinsights.bitdefender.com/topic/endpoint-protection-management)
- [Endpoint Detection and Response (124)](https://businessinsights.bitdefender.com/topic/endpoint-detection-and-response)
- [Managed Detection and Response (119)](https://businessinsights.bitdefender.com/topic/managed-detection-and-response)
- [Virtualization & Data Center Security (82)](https://businessinsights.bitdefender.com/topic/virtualization-data-center-security)
- [Threat Intelligence (76)](https://businessinsights.bitdefender.com/topic/threat-intelligence)
- [IT Compliance & Regulations (71)](https://businessinsights.bitdefender.com/topic/it-compliance-regulations)
- [Bitdefender Threat Debrief (55)](https://businessinsights.bitdefender.com/topic/bitdefender-threat-debrief)
- [Managed Service Providers (53)](https://businessinsights.bitdefender.com/topic/managed-service-providers)
- [#Featured (52)](https://businessinsights.bitdefender.com/topic/featured)
- [Advanced Persistent Threats (46)](https://businessinsights.bitdefender.com/topic/advanced-persistent-threats)
- [Events (38)](https://businessinsights.bitdefender.com/topic/events)
- [Independent Testing (18)](https://businessinsights.bitdefender.com/topic/independent-testing)
- [Cybersecurity Advisory Services (9)](https://businessinsights.bitdefender.com/topic/cybersecurity-advisory-services)
- [Podcast (3)](https://businessinsights.bitdefender.com/topic/podcast)
- [top (2)](https://businessinsights.bitdefender.com/topic/top)

See all topics

### Subscribe to Blog Updates

## Read more about this topic

<https://businessinsights.bitdefender.com/amazon-stop-s3-buckets-leaking-data?hsLang=en-us>

### [Amazon moves to stop S3 buckets leaking business data](https://businessinsights.bitdefender.com/amazon-stop-s3-buckets-leaking-data?hsLang=en-us)

<https://businessinsights.bitdefender.com/worst-amazon-breaches?hsLang=en-us>

### [Leaky Buckets: 10 Worst Amazon S3 Breaches](https://businessinsights.bitdefender.com/worst-amazon-breaches?hsLang=en-us)

<https://businessinsights.bitdefender.com/security-alerts-actionable-insights-context-can-save-you-time-money?hsLang=en-us>

### [From Security Alerts to Actionable Insights. How Context Can Save You Time and Money](https://businessinsights.bitdefender.com/security-alerts-actionable-insights-context-can-save-you-time-money?hsLang=en-us)

![bitdefender](https://businessinsights.bitdefender.com/hs-fs/file-2685110570-png/Bitdefender-Mar2015-Theme/Images/avatar_img_footer.png)

![bitdefender](https://businessinsights.bitdefender.com/hs-fs/file-2676149282-png/Bitdefender-Mar2015-Theme/Images/logo_white_footer.png)

- [![https://twitter.com/Bitdefender_Ent](https://businessinsights.bitdefender.com/hs-fs/file-2658233851-png/Bitdefender-Mar2015-Theme/Images/ft_soc_tw.png?width=33&name=ft_soc_tw.png)](https://twitter.com/Bitdefender_Ent)
- [![Linkedin-icon-300x300](https://businessinsights.bitdefender.com/hs-fs/hubfs/Bitdefender-Mar2015-Theme/Images/Linkedin-icon-300x300.png?width=33&name=Linkedin-icon-300x300.png)](https://www.linkedin.com/company/bitdefender-gravityzone-enterprise-security)
- [![](https://businessinsights.bitdefender.com/hs-fs/file-2676149307-png/Bitdefender-Mar2015-Theme/Images/ft_soc_yt.png)](https://www.youtube.com/user/BitdefenderSecurity)

- [Legal Terms](https://www.bitdefender.com/legal/)
- [Privacy Policy](https://www.bitdefender.com/site/view/legal-privacy-policy-for-bitdefender-websites.html)
- [EULA](https://www.bitdefender.com/site/view/legal-eula.html)
- [Contact Us](https://www.bitdefender.com/business/contact.html)

Copyright © 1997-2023 Bitdefender All rights reserved.

![](https://px.spiceworks.com/px/5rec)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Graham Cluley",
    "url" : "https://businessinsights.bitdefender.com/author/graham-cluley"
  },
  "dateModified" : "2019-12-07T08:15:00.353Z",
  "datePublished" : "2019-12-07T08:15:00.000Z",
  "headline" : "Amazon Battles Leaky S3 Buckets with a New Security Tool",
  "image" : [ "https://businessinsights.bitdefender.com/hubfs/buckets.jpeg" ],
  "mainEntityOfPage" : {
    "@id" : "https://businessinsights.bitdefender.com/amazon-battles-leaky-s3-buckets-with-a-new-security-tool",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://businessinsights.bitdefender.com/hubfs/Bitdefender_Logo_Transparent-2.png"
    },
    "name" : "Bitdefender"
  }
}
```