2016 Sentry — Misconfigured S3 backup bucket
Data compromised
User accounts; API tokens (in backups)
Technical writeup
S3 bucket containing partial database backups (user accounts, API tokens) had incorrect ACLs allowing any authenticated AWS user to access. No evidence of data access; Sentry rotated credentials, moved buckets, added password expiration.
Root cause
Misconfigured AWS S3 bucket permissions