Get notified of our articles as they're available
Your data is safe - no sharing, no spam.
Football Australia exposed a long-term AWS access key in the source code of its public website and, according to the incident details, that key granted access to 126 S3 buckets containing sensitive player and fan information.
aws s3
FTX’s November 2022 breach was not an isolated intrusion but the result of extreme cloud governance and security control failure across a high-value crypto platform, with management stating the environment had already been compromised and lacked the controls to detect or stop the theft of approximately $432 million in crypto assets.
aws everything
In February 2018, The Los Angeles Times served Coinhive cryptomining code to visitors after an unauthorised party modified JavaScript in an AWS S3 bucket that allowed public write access, with first known evidence dating to February 9 and removal on February 22.
s3 aws
CrowdStrike’s 2026 Global Threat Report describes a 2025 threat landscape where adversaries used AI, automation, valid credentials, trusted SaaS paths and supply chain compromise to move faster and evade traditional controls.
ai compromise
The below article from the Register establishes a clear security incident pattern: leaked tokens and credentials can be collected at scale through automated tooling, then reused through downstream tooling to access services and expand compromise.
iam compromise
Microsoft disclosed that Midnight Blizzard used a password spray attack against a legacy non-production test tenant account, then accessed a small number of corporate email accounts belonging to senior leadership and employees in security and legal roles. The incident is notable not just for the weak password and lack of MFA, but for the apparent trust relationship that allowed a test account to reach production-sensitive resources.
iam data loss
Wiz Research’s review of Microsoft’s September 2023 Storm-0558 update points to compound failures: a highly sensitive MSA signing key was exposed through crash dump handling, remained valid long after its stated expiry and was then usable because Exchange accepted tokens under flawed issuer validation logic.
iam data loss
TigerSwan exposed thousands of applicant resumes through a publicly accessible AWS S3 bucket identified by UpGuard in July 2017, with the repository remaining open until August 24 despite repeated notification. The incident combines two recurring enterprise failures: insecure third-party handling of sensitive data and weak cloud governance over internet-accessible storage.
data loss s3 aws
Capital One disclosed a data security incident affecting approximately 100 million individuals in the United States and Canada, including personal information, customer status data, 140,000 Social Security numbers, about 80,000 linked bank account numbers and approximately 1 million Canadian Social Insurance Numbers.
aws data loss iam s3
A production configuration failure exposed highly sensitive Lloyds Bank customer data at scale to users who were authenticated but not authorised to access it, creating a clear access control and governance breakdown in a regulated environment.
caching data loss
A contractor-maintained GitHub repository associated with CISA publicly exposed plaintext passwords, tokens, logs and high-privilege AWS GovCloud credentials, with Seralys validating that at least three exposed AWS accounts were still accessible at a high privilege level.
iam data loss