Amazon Macie Launches (Aug 2017): Machine Learning for Finding Sensitive Data in S3
Retrospective: this article looks back at events from August 2017, written in 2026 with the benefit of hindsight.
In August 2017, AWS launched Amazon Macie, a service that used machine learning to discover, classify and protect sensitive data stored in Amazon S3. It arrived in the middle of a summer of S3 data leaks.
What it did
Macie scanned S3 buckets to find personally identifiable information, credentials and other sensitive content, then monitored access patterns to flag unusual activity. It was built on technology from Harvest.ai, a startup AWS had acquired.
Why it mattered
Most companies did not know what was in their S3 buckets. Data accumulated through exports, backups, logs and application uploads, often without a data owner. Macie offered an automated answer to the question every breach investigation asks first: what was in there?
The early limitations
The first version was expensive at scale and supported a limited set of regions. AWS relaunched Macie in 2020 with a new pricing model, broader availability and multi-account management, which made it far more practical for routine use.
In hindsight
Macie reflected a shift from protecting infrastructure to protecting data. Today, data security posture management is a product category of its own, spanning cloud storage, databases and SaaS — including Microsoft Purview on the Microsoft side. The lesson from 2017 still holds: you can only protect the data you know about, and in the cloud, data multiplies faster than anyone tracks it.
- How to Use Amazon Macie to Discover PII in Your S3 Buckets How-To & Hardening
- Amazon Macie Rollout Checklist: Cost Controls and Finding Triage How-To & Hardening
- CIO Brief: You Can't Protect Data You Haven't Found CIO Briefings