Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

In September 2017, four Accenture AWS S3 buckets were left publicly reachable because of inadequate access controls. Reporting described passwords, cloud credentials, keys, certificates, email data and other internal information among the files. Accenture said the files were not production data and that no active credentials or customer systems were compromised; the available reporting does not establish that an attacker exploited the exposure.

What happened to Accenture’s S3 buckets?

UpGuard researcher Chris Vickery discovered four publicly reachable Accenture buckets on September 17, 2017, and notified the company. SecurityWeek reported that Accenture secured them a few days later. SecurityWeek published its detailed account on October 11, 2017. NTT DATA’s 2017 security-trend timeline also recorded the incident as a confidential-information leak caused by Amazon S3 misconfiguration.

The central failure was inadequate access control on cloud storage: files intended to remain restricted could be reached publicly. The reporting identifies four exposed buckets, but gives a size only for the largest.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What data was exposed?

SecurityWeek reported that the largest bucket contained 137 GB of data, including approximately 40,000 plaintext passwords. The reported contents across the buckets included:

  • Plaintext and hashed passwords.
  • Enstratus cloud-management access keys, along with credentials for Accenture’s Azure and Google accounts.
  • Internal API credentials and configuration files, including an AWS Key Management Service master access key.
  • Private signing keys, certificates and VPN keys.
  • Email data, ASGARD database information and other customer-related data.

Plaintext passwords and hashed passwords are not equivalent exposures: plaintext values can be read directly, while hashes require additional work to recover the original passwords. Both can create risk, particularly if credentials are reused. The specific report’s figure of approximately 40,000 refers to plaintext passwords, not a combined count of all passwords or credentials.

Could the exposed keys have enabled access or decryption?

UpGuard warned that the exposed credentials and keys could create risks such as impersonation or unauthorized access to cloud resources. It also said some private keys and certificates might have allowed an attacker to decrypt traffic between Accenture and clients. These were assessments of potential consequences, not reports that those actions occurred.

Accenture said none of the exposed files was production data, no active credentials or customer systems were compromised, and its controls would have detected intrusion attempts. The available reporting does not document a successful exploit, confirmed attacker access, customer notification, regulatory penalty or independently audited loss total. Public exposure of a credential is serious even when misuse is not established, but exposure alone does not prove that anyone used it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How should organizations prevent a public cloud-storage leak?

The incident illustrates why storage security needs both preventive controls and ongoing checks. A bucket that is private today can become exposed after a policy or configuration change, so review should cover the configuration over time as well as at setup.

Block unintended public access

Set storage private by default and require an explicit, approved reason for public access. Apply public-access prevention at the account and storage-resource levels where available, and review bucket policies and access-control settings before deployment. Treat exceptions as scoped, documented decisions rather than broad permissions.

Continuously detect policy changes

Test storage policies regularly and monitor for configuration drift that makes a bucket or its contents publicly reachable. Alert on changes to access policies and investigate unexpected access patterns. A one-time setup review will not catch every later change.

Keep secrets out of stored files

Do not store plaintext passwords, long-lived access keys or other secrets in files that may be copied into cloud storage. Use managed secret storage and limit credential permissions to the resources and actions required. If a secret is exposed, revoke or rotate it promptly; removing the file alone does not invalidate a credential that may already have been copied.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Limit access and prepare to respond

Apply least privilege to identities that can read, write or change storage permissions. Maintain access logs and alerts that help distinguish expected activity from unusual reads or policy changes. Include cloud credentials and stored secrets in incident-response procedures so teams can assess exposure, contain access and rotate affected credentials.

For organizations managing multiple cloud platforms, the same checks should cover AWS, Azure and Google Cloud rather than only the storage service involved in a particular incident. Cloud security posture management, S3 bucket monitoring and cloud-secrets detection are relevant categories of controls; their value depends on whether they cover the organization’s actual accounts, policies and response process.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.