logo

New Bucket Hijacking Attack Allows Hackers to Reroute Cloud Data Streams to External Storage

ID: 3e680027-a119-510b-998f-e0b8228405c9

STIX ID: report--3e680027-a119-510b-998f-e0b8228405c9

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-06-27

Date Updated: 2026-06-27

Author: Guru Baran

...
...

Unit 42 describes a critical "bucket hijacking" technique that leverages globally-unique cloud storage names: an attacker who can delete a victim's storage bucket can recreate the same-named bucket under their control, causing logging sinks, replication, and telemetry to be silently redirected into attacker-owned buckets across Google Cloud, AWS, and Azure; the attack is stealthy because sinks continue to report as valid, and recommended defenses include restricting deletion permissions, enforcing perimeter controls (SCPs/VPC Service Controls), enabling account-scoped namespaces, and alerting on bucket deletion API calls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.