How to Find and Lock Down Public S3 Buckets Across Every AWS Account
Retrospective: this article looks back at events from June 2017, written in 2026 with the benefit of hindsight.
Public S3 buckets were behind dozens of data leaks in 2017. AWS has since made buckets private by default, but older accounts, older buckets and deliberate exceptions still create exposure. Here is how to find and lock down public buckets across every AWS account you own.
Step 1: Get an organization-wide view
If you use AWS Organizations, enable IAM Access Analyzer with the organization as the zone of trust. It reports buckets shared publicly or with external accounts, across all member accounts.
Step 2: Check the S3 console signals
The S3 console shows an "Access" column flagging buckets that are public or "Objects can be public." Review every flagged bucket with its owner.
Step 3: Turn on Block Public Access at the account level
For every account, enable all four S3 Block Public Access settings at the account level unless a bucket genuinely must serve public content:
aws s3control put-public-access-block --account-id 111122223333 \
--public-access-block-configuration BlockPublicAcls=true,IgnorePublicAcls=true,BlockPublicPolicy=true,RestrictPublicBuckets=true
Step 4: Handle legitimate public content properly
Websites and public downloads should be served through CloudFront with Origin Access Control, so the bucket itself stays private.
Step 5: Prevent drift
- Use an SCP to deny changes to the account-level Block Public Access settings.
- Enable AWS Config rules for public read and write access and route findings to Security Hub.
Common mistakes
- Checking only bucket policies and forgetting object-level ACLs on older buckets.
- Granting access to "any authenticated AWS user," which means any AWS account in the world.
- Fixing the bucket but not rotating any credentials or secrets that were stored in it.