2017 Booz Allen Hamilton — public Amazon S3 bucket exposed sensitive NGA project artifacts (researcher disclosure)
Data compromised
Infrastructure credentials and sensitive but unclassified program support files per outlet analyses
Technical writeup
In May–June 2017, security researchers disclosed a misconfigured Amazon S3 bucket tied to Booz Allen work for NGA, revealing credentials, SSH keys, and geospatial/intel-supporting files in plaintext public exposure narratives. Booz Allen told press partners it saw no classified material in the dataset and treated remediation seriously.
Root cause
Cloud object storage misconfiguration enabling unauthenticated public reads