APT-level red team operations for enterprises and organizations
CASE FILE RT-0226 Retail / e-commerce

A public bucket nobody owned

Not every breach is an attack. Some are an absence of housekeeping: a bucket left public for three years, generating exactly zero evidence of its own existence.

Objective
Read customer PII in a cloud data lake without any credentials or exploit
Path
An external surface audit found a storage bucket left over from a three-year-old migration project: public listing enabled, server-side access logs disabled, owner team dissolved in a reorg. 2.3 GB of semi-anonymized customer records with order history sat readable to anyone with the URL — discoverable only by guessable naming. No exploit was needed and no authentication event was ever generated: the gap produced zero telemetry for three years.
Detected
Nothing to detect: public object storage generates no auth logs, and inventory reviews stopped when the owning team was dissolved

After: Public access blocked at the organization-policy level, an automated quarterly bucket inventory with ownership tags, and PII moved behind a query gateway with audit logging.

Names, sectors and infrastructure details are changed; timelines and tradecraft are not. More case files →

The pattern in one page

  • Storage drifts to public during migrations — audit continuously, not yearly.
  • If access generates no logs, it cannot be detected. Move PII behind logged gateways.
  • Every bucket needs a named owner — reorgs are where ownership goes to die.
Recognize the pattern?
We can verifyTypical effort
The same path against your estate, under signed ROE2–4 wks
Detection validation: what your SOC would have seenincluded
Retest after fixes, within three monthsfree

Could this path exist in your estate?

Tell us your crown jewels — we will tell you how close this case file is to your reality.

Request assessment