• News/
  • https://www.theregister.com/2025/02/04/abandoned_aws_s3/

Abandoned AWS S3 buckets can be reused in supply-chain attacks that would make SolarWinds look 'insignificant'

The Register
·
Jessica Lyons
·
Published Feb 4, 2025
·
Updated

Abandoned AWS S3 buckets could be reused to hijack the global software supply chain in an attack that would make Russia's "SolarWinds adventures look amateurish and insignificant," watchTowr Labs security researchers have claimed. The researchers, in a report due out this morning, say they identified about 150 Amazon-hosted cloud storage buckets that were long gone yet applications and websites were still trying to pull software updates and other code from them. If someone were to take over those buckets, they could use them to feed malicious software into people's devices. These S3 buckets had previously been owned or used by governments, Fortune 500 firms, technology and cybersecurity companies, and major open source projects. The watchTowr team said it spent $420.85 to re-register these S3 buckets with the same names and enabled logging for all of them to track which files were being requested still and by what. They told us they spent two months watching the HTTP requests roll in. During this time, the S3 buckets received more than eight million requests for resources including Windows, Linux, and macOS executables; virtual machine images; JavaScript files; CloudFormation templates; and SSL VPN server configurations, the watchTowr crew said. These incoming requests came from NASA and other US government networks, along with government orgs in the UK and other countries, judging from domain records. Military networks, plus those belonging to Fortune 500 and Fortune 100 com...

Read full article

Affected Software

2 affected components
Amazon AWS S3
Amazon S3
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the security risks associated with abandoned AWS S3 buckets and their potential for facilitating supply chain attacks.

2

What security implications are discussed in this article?

The article highlights that abandoned AWS S3 buckets can be exploited for malicious purposes, potentially making large-scale attacks on the software supply chain more significant than previous incidents like SolarWinds.

3

What products or software are affected by the issues discussed?

The primary affected product mentioned in the article is Amazon AWS S3.

4

How could abandoned AWS S3 buckets be exploited?

Abandoned AWS S3 buckets could be reused by attackers to inject malicious code or data into legitimate software distributions.

5

What comparisons are made regarding the severity of potential attacks?

The article compares the potential scale and sophistication of attacks using abandoned AWS S3 buckets to those seen in the SolarWinds incident, suggesting they could be far worse.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203