iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
In 2017, SC Media reported that more than 60,000 files linked to National Geospatial-Intelligence Agency work were accessible on an unsecured Amazon server. The files reportedly included passwords and SSH keys. The available account did not establish whether Booz Allen Hamilton or Metronome was responsible, and it did not show that anyone used the credentials.
What was reportedly exposed?
SC Media reported that the exposed dataset contained more than 60,000 files associated with work for the National Geospatial-Intelligence Agency (NGA), including passwords and SSH keys. The report said domain registrations and credentials in the data pointed toward Booz Allen Hamilton or Metronome. UpGuard, which identified the exposure, could not definitively determine which contractor was responsible, according to the SC Media report.
The report described an unsecured Amazon server, but the available account does not establish the exact storage configuration, how long the files were accessible, or the precise sequence that led to the exposure.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Were the files classified?
An NGA spokesperson characterized the information as sensitive but not classified and said affected credentials were revoked. Booz Allen said that it and its client had confirmed no classified data was available in the impacted unclassified cloud environments. The company described the incident as an employee unintentionally leaving a key in an unclassified cloud environment; it said it secured the area, notified its client, and began an investigation.
#1 Best Overall
Those are statements attributed to the agency and company in the reporting, not independent verification of every exposed file. The account supports describing the material as reported to be sensitive but unclassified; it does not establish the exact contents of every file.
Did anyone use the passwords or SSH keys?
The reporting does not establish that anyone used the exposed credentials or gained access to another system. Security commentator Zohar Alon warned that passwords and SSH keys could potentially provide a path to more sensitive systems. That is a risk scenario, not evidence of exploitation or a confirmed follow-on breach.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How can an organization reduce the risk of public S3 exposure?
The 2017 account does not say which AWS controls were configured in the incident. Current AWS guidance describes several measures organizations can use to prevent unintended public access and find sensitive data:
Block public access centrally
AWS S3 Block Public Access settings are available at the organization, account, bucket, and access-point levels. They override policies and permissions that would otherwise allow public access. AWS recommends enabling all four settings when they are compatible with the application’s intended use. See AWS documentation for S3 Block Public Access.
Assess public access and discover sensitive data
Amazon Macie can evaluate whether an S3 bucket is publicly accessible by considering Block Public Access settings, bucket policies, and access control lists. It can also analyze selected S3 objects for sensitive data. Macie’s automated discovery samples representative objects, so it is a discovery aid—not a guarantee that every object has been inspected. Coverage depends on the configured scope and supported data. See AWS documentation for Macie sensitive-data discovery.
These controls address different questions: Block Public Access is a preventive access control, while Macie helps assess access and identify sensitive information. Neither should be treated as proof that a particular bucket is safe on its own.
Quick Recap
Best Value
- Used Book in Good Condition
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →

