Several UK consulting firms recently left an Amazon Web Services (AWS) Simple Storage Service (S3) bucket open, according to vpnMentor. Sensitive information from thousands of British professionals was exposed due to the open S3 bucket, which was closed Dec. 19, 2019.
Sensitive information exposed by the UK consulting firms' data leak included:
The data leak was discovered Dec. 9, 2019 and traced back to CHS Consulting, a London-based consulting firm. It contained files belonging to various UK consulting firms, including:
Most of the exposed information dated back to 2014-2015, vpnMentor reported. However, some exposed files dated back to 2011.
Global Organizations Suffer AWS Data Leaks
Several global organizations recently experienced AWS data leaks, including:
AWS Access Analyzer: Mitigating Configuration Risks
To mitigate such risks, AWS in December 2019 month announced Access Analyzer to help organizations minimize the risk of S3 bucket data leaks.
Access Analyzer notifies an organization if it has an S3 bucket that is configured to allow access to anyone on the Internet or is shared with other AWS accounts, AWS stated. It also enables an organization to evaluate its S3 bucket-level permission settings and ensure that only authorized users can access an S3 bucket.