Business
Individual
Partners
Intelligence
How we work
Sign in Check my firm
Glossary › Patterns › Cloud misconfiguration
Reference · Pattern

S3 bucket permissions allowing anonymous list

Severity HighKind Cloud misconfigurationEffort to fix TrivialUpdated 29 Sep 2026By LeakTrace
Definition

A production or backup S3 bucket is configured to allow anonymous LIST operations, exposing the object inventory (and often the object contents) to any unauthenticated caller.

What it is

S3 bucket permissions are famously easy to misconfigure. A single toggle can flip a private bucket to allow anonymous LIST operations, which reveals every object key, often including customer names, invoice numbers, backup timestamps, and internal document titles that are never meant to be public. In many cases the objects themselves are also anonymously readable.

Why it matters

Automated bucket-enumeration tools scan for buckets named with corporate patterns (<company>-backup, <company>-prod, <company>-media) and index every publicly listable one. The resulting object lists are then processed for high-value keys (invoices, contracts, exports, database dumps) and either sold on underground markets or used directly for pretext against the firm.

How anyone can check it

curl -s https://your-bucket.s3.amazonaws.com/

If the reply lists file names, anyone can list the bucket.

Remediation direction

Immediate: enable S3 Block Public Access at the account level; review every bucket for public ACL or bucket-policy grants. Longer term: enforce a mandatory bucket-tagging + review workflow so no new bucket goes production without an explicit privacy-review sign-off.

LeakTrace does not perform the fix. In an assessment, every finding carries a step-by-step remediation for the firm’s IT provider.

See what is open from outside before anyone else does. Check my firm →