Nearly 20 Billion Files Exposed Due to Misconfigured Cloud Buckets

Nearly 20 Billion Files Exposed Due to Misconfigured Cloud Buckets

First seen 29 May 2026, 18:41 UTC Securityaffairs.CoFeeds.Feedburner 80% similarity 69.0

Article Content

Browse articles
ThreatCluster

Researchers from Mysterium VPN reported that nearly 20 billion files have been exposed due to misconfigured cloud storage buckets across major providers like Amazon S3, Google Cloud, and Azure. The exposed files include 685,047 credential files and nearly 1 million database dumps, all accessible without authentication. The issue stems from user misconfigurations rather than vulnerabilities in the cloud platforms themselves. Amazon S3 accounts for over two-thirds of the exposed storage. The interconnectedness of these files increases the risk of complete data breaches from a single misconfigured bucket. Recommendations for mitigation include defaulting to private settings, avoiding the storage of sensitive data in object storage, and implementing regular vulnerability scans. Users are advised to use unique passwords and enable multi-factor authentication. The report emphasizes the urgent need for better security practices among cloud storage users.

Key Points: • Nearly 20 billion files exposed due to misconfigured cloud storage buckets. • Exposed data includes 685K credential files and nearly 1M database dumps. • Amazon S3 accounts for over two-thirds of the exposed storage.

ThreatCluster AI

Timeline

2026-05-28
Research findings published
Mysterium VPN disclosed that 19.6 billion files are exposed in misconfigured cloud buckets, highlighting the scale of the issue.
Securityaffairs.Co
2026-05-29
Security report released
A report from Security Affairs confirmed the exposure of nearly 20 billion files, detailing the types of sensitive data at risk.
Feeds.Feedburner

Community

Browse all →

Tracked Entities in This Story