- Objective
- Read customer PII in a cloud data lake without any credentials or exploit
- Path
- An external surface audit found a storage bucket left over from a three-year-old migration project: public listing enabled, server-side access logs disabled, owner team dissolved in a reorg. 2.3 GB of semi-anonymized customer records with order history sat readable to anyone with the URL — discoverable only by guessable naming. No exploit was needed and no authentication event was ever generated: the gap produced zero telemetry for three years.
- Detected
- Nothing to detect: public object storage generates no auth logs, and inventory reviews stopped when the owning team was dissolved
After: Public access blocked at the organization-policy level, an automated quarterly bucket inventory with ownership tags, and PII moved behind a query gateway with audit logging.