US Defense Department's Centcom found hosting at least 1.8B posts of scraped internet content from last 8 years on open AWS server
There are two big WTFs in this story. First, the Defense Departments Central Command (Centcom) was collecting tons of data on social media posts …
Context & Ripple Effects
This finding sits inside a decade-long arc of US military mass collection colliding with sloppy cloud hygiene. Centcom had already been burned publicly once before, when the CENTCOM Twitter hack exposed how fragmented and insecure the government's sprawling social media presence was across thousands of accounts. The scraping operation itself is the mirror image of that problem: rather than securing its own accounts, the command was quietly hoovering up everyone else's posts for eight years.
What makes the disclosure consequential is where the archive lived — an open AWS bucket, meaning the Defense Department was outsourcing its most sensitive bulk-collection storage to the same commercial cloud whose configuration defaults it apparently never checked. The pattern did not stop here: weeks later a researcher found 100GB of Army and NSA intelligence data on another unsecured AWS server, and years on, a DOD Azure database sat passwordless for two weeks with years of personnel emails.
First-order effects
- At least 1.8 billion posts of scraped internet content spanning eight years were readable by anyone who found the server, exposing both the scale of Centcom's collection program and the identities or activity of anyone captured in it.
- AWS is cast in the story as infrastructure host to a government surveillance archive it may not have known about, putting its shared-responsibility security model under immediate public scrutiny.
Second-order effects
- Every other agency running bulk collection on commercial cloud now faces pressure to audit its own buckets, since researchers demonstrably know how to find these exposures — as the follow-on Army/NSA discovery confirmed within days.
- The episode strengthens the case for vendors like Team Cymru, whose Augury tooling later won purchases across multiple military branches, positioning managed intelligence infrastructure as the 'safer' alternative to self-hosted scrapes.
Third-order effects
- If the pattern holds — bulk collection growing faster than operational security, from open buckets to passwordless databases — oversight shifts toward forcing the Defense Department to justify what it collects against its demonstrated inability to protect it.
- Commercial cloud becomes the de facto backbone of state surveillance, which pulls providers like AWS into accountability debates they were never designed for: their default configurations are now a matter of national-security policy.
The trend: US military intelligence is migrating its bulk-collection archives onto commercial cloud faster than it can secure them, turning recurring researcher discoveries into a structural argument against unconstrained scraping programs.