News broke last week that sensitive data was yet again leaked… yeah, this is the same song we sing almost every week, but that’s kind of the point.  Our running analogy, “sometimes it feels like we are living in the cybersecurity version of the movie Groundhog Day,” becomes more apt with every passing day.

So what happened this time?

As reported by Zack Day, Security Editor for ZD Net, Robocent, a Virginia-based political campaign and robocalling company, left a massive batch of files containing hundreds of thousands of voter records on a public and exposed Amazon S3 bucket that anyone could access without a password.

Another misconfigured S3 bucket …

According to statistics from Bitdefender, as many as 7% of all S3 servers are entirely publicly accessible without any authentication, and 35% are unencrypted. If you dig through some of the recent leaks caused by poorly configured Amazon S3 resources, “these aren’t low-value data stores.”

Recent leaks caused by leaky S3 buckets:

These are just a few of the companies that have exposed sensitive, personal information for hundreds of millions of people from around the world.

