← Sentry

2016 Sentry — Misconfigured S3 backup bucket

2016 Unknown records affected Share on X

Data compromised

User accounts; API tokens (in backups)

Technical writeup

S3 bucket containing partial database backups (user accounts, API tokens) had incorrect ACLs allowing any authenticated AWS user to access. No evidence of data access; Sentry rotated credentials, moved buckets, added password expiration.

Root cause

Misconfigured AWS S3 bucket permissions

References