logo

Abandoned AWS Cloud Storage: A Major Cyberattack Vector

ID: ac39e3e2-1c1e-57dc-bf66-817e84fe2cca

STIX ID: report--ac39e3e2-1c1e-57dc-bf66-817e84fe2cca

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2025-02-05

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Researchers at watchTowr discovered that abandoned cloud storage buckets (AWS S3) referenced in deployment code and update mechanisms can be re-registered by attackers and used to deliver malware, malicious updates, or backdoored templates; they registered ~150 such buckets for ~$400, enabled logging, and observed ~8 million requests over two months from government agencies, Fortune 100 companies, banks, and security vendors. The study highlights a severe supply-chain/abandoned-infrastructure weakness, and while the researchers did not deploy malware, the implications are high; AWS subsequently blocked re-creation of the identified buckets and advised customers on best practices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.