Cloud Security & Infrastructure HardeningSetup guide3 min readUpdated September 2026

How to Find Publicly Exposed S3 Buckets in Your Account

To find public S3 buckets in your AWS account, enable account-level Block Public Access, list every bucket, then check each bucket's public access settings, policy status and ACLs, and review IAM Access Analyzer findings. Then fix what shouldn't be public and alert on new exposure.

Only test buckets you own or are authorized to assess. Probing other people's buckets can be illegal.

Vendors Covered in this Article

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

How do you inventory every bucket first?

You can't secure what you haven't listed. Buckets hide in old accounts, in regions you forgot, and in accounts created by acquisitions or experiments.

  1. List accounts: use your AWS Organizations list, and check billing for accounts nobody remembers.
  2. In each account, list buckets with the S3 console or aws s3api list-buckets.
  3. Record the owner, purpose, data type and whether it's supposed to serve the public, such as a website or downloads.
  4. Mark buckets with no owner. Those need attention first, because nobody will notice if they're exposed.

A spreadsheet is enough at first. The goal is a list with a column for 'intended to be public: yes or no'.

What checks show that a bucket is public?

Several settings interact, so check each layer:

  • Block Public Access: run aws s3api get-public-access-block for the bucket and aws s3control get-public-access-block for the account. All four settings on means public policies and ACLs are ignored or rejected.
  • Policy status: aws s3api get-bucket-policy-status returns whether the bucket policy makes it public.
  • Bucket policy: look for statements with a Principal of * that allow s3:GetObject or s3:ListBucket, and check conditions that might narrow them.
  • ACLs: aws s3api get-bucket-acl shows grants to AllUsers or AuthenticatedUsers. Object-level ACLs can also make individual objects public.
  • Access analyzer: IAM Access Analyzer for S3 flags buckets that allow access from outside your account or to the public.

Also check indirect exposure: a CloudFront distribution in front of a bucket, a pre-signed URL that never expires, or a bucket that lets any authenticated AWS user read it.

How to fix what you find

Decide bucket by bucket whether public access is intended. For public websites and assets, prefer serving through a CDN with origin access controls and keeping the bucket itself private. For everything else, the fix is to remove the public policy and ACL grants and turn on Block Public Access.

Before flipping settings on a bucket that supports a live site, look at access logs or CloudTrail data events to see who reads it, otherwise you may break downloads that customers rely on. After the change, check the objects too, since an object with a public ACL can stay accessible until you fix that. If sensitive data was exposed, treat it as a security incident, preserve logs, and ask your attorney about notification duties, which depend on the data and your customers' locations.

How do you keep it from happening again?

One-off scans decay. Put guardrails in place:

  • Enable Block Public Access at the account level, and use an organization policy so new accounts inherit it.
  • Turn on AWS Config rules or Security Hub controls that flag public buckets, and route alerts to a channel someone reads. The setup context is in the AWS security baseline checklist.
  • Require infrastructure code review for bucket policy changes.
  • Tag every bucket with an owner and data classification.
  • If you have many accounts, a cloud security posture tool like Wiz can scan all of them together and show which exposed buckets hold sensitive data.

For background on that tool category, read CSPM explained for small teams and the product comparison in Wiz vs Prisma Cloud vs AWS Security Hub.

What does an outside-in check add?

Internal settings tell you what AWS thinks. An outside-in test tells you what an anonymous visitor can do. For buckets you own, try an unauthenticated list and a get request against a few known object names from a machine without your credentials. Anyone can guess names from your company, product and environment patterns, so assume attackers try the same. If a test succeeds where you expected denial, look for the layer you missed. Run these checks on a schedule, not once.

Executive Capability Standard

What Good Looks Like

Block Public Access is on at the account level, every bucket has an owner and a stated public or private intent, and new exposure triggers an alert.

Building The Capability (5-Stage Skill Ladder)

1. Learn:Read how Block Public Access, bucket policies and ACLs combine, and list which of your buckets are meant to be public.
2. Do Manually:Run the access checks on every bucket in every account and record findings in a spreadsheet.
3. Delegate:Assign each bucket an owner and ask them to confirm its purpose and public status quarterly.
4. Automate:Enable Config rules or Security Hub controls for public buckets and send alerts to the team channel.
5. Buy:Add a cloud security posture tool for cross-account visibility once you run many accounts.

How to Get Started

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

Frequently Asked Questions

What is S3 Block Public Access?

It's a set of controls, available per bucket and per account, that override public policies and ACLs so they can't make data public. Enabling it at the account level is the strongest single guardrail.

How can I tell if an S3 bucket is public?

Check Block Public Access, the bucket policy status, policy statements with a wildcard principal, ACL grants to all users, and IAM Access Analyzer findings. Also test anonymously against buckets you own.

Is a public bucket always a problem?

No. Static websites and downloads may be intentionally public. The problem is unintended exposure. Record which buckets are meant to be public and prefer serving them through a CDN while keeping the bucket private.

Can I scan someone else's S3 buckets?

Not without permission. Testing buckets you don't own can be unlawful and may violate terms of service. Limit assessments to your own accounts or explicitly authorized targets, and get legal advice for research.

About the numbers

This guide doesn't quote a sourced benchmark. Figures in it are estimates or general guidance, so check them against your own numbers.

Related Guides