The S3 leak story has been told a thousand times — and yet, in 2026, public buckets still drive a meaningful share of accidental data exposures. Why?
- Defaults aren't enough. AWS made buckets private-by-default in 2018, but legacy buckets, third-party tools, and one-click "share with anyone" features still create exposure paths.
- Permissions are layered. Bucket policy, ACL, IAM policy, account-level Block Public Access, organization-level SCPs — five places to get wrong.
- Audits are point-in-time. A bucket created two minutes after the last scan may not show up until next week.