How to Find Publicly Exposed S3 Buckets in Your Account
To find public S3 buckets in your AWS account, enable account-level Block Public Access, list every bucket, then check each bucket's public access settings, policy status and ACLs, and review IAM Access Analyzer findings. Then fix what shouldn't be public and alert on new exposure.
Only test buckets you own or are authorized to assess. Probing other people's buckets can be illegal.
Vendors Covered in this Article
Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.
How do you inventory every bucket first?
You can't secure what you haven't listed. Buckets hide in old accounts, in regions you forgot, and in accounts created by acquisitions or experiments.
- List accounts: use your AWS Organizations list, and check billing for accounts nobody remembers.
- In each account, list buckets with the S3 console or aws s3api list-buckets.
- Record the owner, purpose, data type and whether it's supposed to serve the public, such as a website or downloads.
- Mark buckets with no owner. Those need attention first, because nobody will notice if they're exposed.
A spreadsheet is enough at first. The goal is a list with a column for 'intended to be public: yes or no'.
What checks show that a bucket is public?
Several settings interact, so check each layer:
- Block Public Access: run aws s3api get-public-access-block for the bucket and aws s3control get-public-access-block for the account. All four settings on means public policies and ACLs are ignored or rejected.
- Policy status: aws s3api get-bucket-policy-status returns whether the bucket policy makes it public.
- Bucket policy: look for statements with a Principal of * that allow s3:GetObject or s3:ListBucket, and check conditions that might narrow them.
- ACLs: aws s3api get-bucket-acl shows grants to AllUsers or AuthenticatedUsers. Object-level ACLs can also make individual objects public.
- Access analyzer: IAM Access Analyzer for S3 flags buckets that allow access from outside your account or to the public.
Also check indirect exposure: a CloudFront distribution in front of a bucket, a pre-signed URL that never expires, or a bucket that lets any authenticated AWS user read it.
How to fix what you find
Decide bucket by bucket whether public access is intended. For public websites and assets, prefer serving through a CDN with origin access controls and keeping the bucket itself private. For everything else, the fix is to remove the public policy and ACL grants and turn on Block Public Access.
Before flipping settings on a bucket that supports a live site, look at access logs or CloudTrail data events to see who reads it, otherwise you may break downloads that customers rely on. After the change, check the objects too, since an object with a public ACL can stay accessible until you fix that. If sensitive data was exposed, treat it as a security incident, preserve logs, and ask your attorney about notification duties, which depend on the data and your customers' locations.
How do you keep it from happening again?
One-off scans decay. Put guardrails in place:
- Enable Block Public Access at the account level, and use an organization policy so new accounts inherit it.
- Turn on AWS Config rules or Security Hub controls that flag public buckets, and route alerts to a channel someone reads. The setup context is in the AWS security baseline checklist.
- Require infrastructure code review for bucket policy changes.
- Tag every bucket with an owner and data classification.
- If you have many accounts, a cloud security posture tool like Wiz can scan all of them together and show which exposed buckets hold sensitive data.
For background on that tool category, read CSPM explained for small teams and the product comparison in Wiz vs Prisma Cloud vs AWS Security Hub.
What does an outside-in check add?
Internal settings tell you what AWS thinks. An outside-in test tells you what an anonymous visitor can do. For buckets you own, try an unauthenticated list and a get request against a few known object names from a machine without your credentials. Anyone can guess names from your company, product and environment patterns, so assume attackers try the same. If a test succeeds where you expected denial, look for the layer you missed. Run these checks on a schedule, not once.
What Good Looks Like
Block Public Access is on at the account level, every bucket has an owner and a stated public or private intent, and new exposure triggers an alert.
Building The Capability (5-Stage Skill Ladder)
How to Get Started
Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.
Frequently Asked Questions
What is S3 Block Public Access?
It's a set of controls, available per bucket and per account, that override public policies and ACLs so they can't make data public. Enabling it at the account level is the strongest single guardrail.
How can I tell if an S3 bucket is public?
Check Block Public Access, the bucket policy status, policy statements with a wildcard principal, ACL grants to all users, and IAM Access Analyzer findings. Also test anonymously against buckets you own.
Is a public bucket always a problem?
No. Static websites and downloads may be intentionally public. The problem is unintended exposure. Record which buckets are meant to be public and prefer serving them through a CDN while keeping the bucket private.
Can I scan someone else's S3 buckets?
Not without permission. Testing buckets you don't own can be unlawful and may violate terms of service. Limit assessments to your own accounts or explicitly authorized targets, and get legal advice for research.
About the numbers
This guide doesn't quote a sourced benchmark. Figures in it are estimates or general guidance, so check them against your own numbers.
Related Guides
AWS Security Baseline: What to Set Up in a New Account
A first-day AWS security checklist for a new account: root user, identity, logging, storage, networking, budgets and monitoring, in the order to do them.
Cloud Security Posture Management (CSPM) for a Small Team
What CSPM is, what it catches, how it differs from other cloud security tools and how a small team can adopt it without drowning in alerts.
Wiz vs Prisma Cloud vs AWS Security Hub: Cloud Security & CSPM Comparison
Compare Wiz, Prisma Cloud, and AWS Security Hub for CNAPP, agentless CSPM, runtime security, container scanning, and multi-cloud compliance.
Wiz vs Prisma Cloud for Data Pipelines That Vanish in Minutes
A data analytics consultancy's real workload is a job cluster that spins up, runs for minutes, and disappears. Here's how Wiz and Prisma Cloud each handle that.