CIO Brief: Storage Misconfiguration Is a Cloud-Agnostic Problem
Retrospective: this article looks back at events from October 2022, written in 2026 with the benefit of hindsight.
The short version: In 2022, researchers reported that a misconfigured Microsoft storage location exposed business documents involving Microsoft's customers. Microsoft disputed the scale but confirmed the misconfiguration. Storage misconfiguration happens in every cloud and to every provider.
Why it's the same story everywhere
Amazon S3 buckets, Azure Blob containers and Google Cloud Storage all have settings that can make data public. Every major cloud provider has had customer and internal incidents caused by them. The fix is the same: prevent public access by default, and monitor for exceptions.
The business impact
- Exposure of contracts, pricing and customer communications.
- Competitive harm if business documents leak.
- Disputes and uncertainty about what was exposed.
Questions to ask your team
- In every cloud we use, is public storage access blocked by default?
- Can anyone change that, or is it enforced centrally?
- How quickly would we know if storage became public?
- Do we use identity-based access instead of shared keys and links?
What good looks like
Public access blocked by policy in every cloud, identity-based access to storage, monitoring for exposure, and a short list of documented exceptions.
The decision
Ask for a single report covering storage exposure across all your cloud providers. If you use more than one cloud, the gaps are often in the one you use least.
- BlueBleed (Oct 2022): Misconfigured Azure Blob Storage Exposes Microsoft Customer Data Incident Teardowns
- How to Audit Azure Storage Accounts for Public Access and Shared Keys How-To & Hardening
- Detecting Azure Blob Public Access: Defender for Cloud and Sentinel KQL Detection & Response