AWSHow-To & HardeningRetrospectives

How to Find and Lock Down Public S3 Buckets Across Every AWS Account

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from June 2017, written in 2026 with the benefit of hindsight.

Public S3 buckets were behind dozens of data leaks in 2017. AWS has since made buckets private by default, but older accounts, older buckets and deliberate exceptions still create exposure. Here is how to find and lock down public buckets across every AWS account you own.

Step 1: Get an organization-wide view

If you use AWS Organizations, enable IAM Access Analyzer with the organization as the zone of trust. It reports buckets shared publicly or with external accounts, across all member accounts.

Step 2: Check the S3 console signals

The S3 console shows an "Access" column flagging buckets that are public or "Objects can be public." Review every flagged bucket with its owner.

Step 3: Turn on Block Public Access at the account level

For every account, enable all four S3 Block Public Access settings at the account level unless a bucket genuinely must serve public content:

aws s3control put-public-access-block --account-id 111122223333 \
  --public-access-block-configuration BlockPublicAcls=true,IgnorePublicAcls=true,BlockPublicPolicy=true,RestrictPublicBuckets=true

Step 4: Handle legitimate public content properly

Websites and public downloads should be served through CloudFront with Origin Access Control, so the bucket itself stays private.

Step 5: Prevent drift

  • Use an SCP to deny changes to the account-level Block Public Access settings.
  • Enable AWS Config rules for public read and write access and route findings to Security Hub.

Common mistakes

  • Checking only bucket policies and forgetting object-level ACLs on older buckets.
  • Granting access to "any authenticated AWS user," which means any AWS account in the world.
  • Fixing the bucket but not rotating any credentials or secrets that were stored in it.
find public s3 bucketsRNC voter data S32017

More on this story