Researcher finds 100GB of US intel data, from US Army and NSA, hosted on unsecured AWS server as disk image, following a string of similar mistakes by US intel
Zack Whittaker / ZDNet :
Context & Ripple Effects
The finding lands in an already crowded file: earlier in 2017 alone, researchers documented a misconfigured backup drive at Stewart International Airport that sat exposed for nearly a year, and Accenture's exposed servers holding 40K unencrypted passwords. The common thread is not sophisticated intrusion but basic cloud misconfiguration — sensitive data placed on public infrastructure without access controls.
What makes this instance notable is the owner: US Army and NSA intelligence material hosted as a downloadable disk image on AWS, meaning the government's own cloud hygiene is now part of the same exposure pattern as contractors and private firms.
First-order effects
- US Army and NSA face immediate exposure questions: whatever was in that 100GB disk image was retrievable by anyone who found the server, forcing an internal review of how classified-adjacent workloads get staged on commercial cloud storage.
- AWS is implicated as infrastructure rather than culprit — its shared-responsibility model means the agency, not the provider, owns the misconfiguration, but the incident still attaches to AWS's government-cloud reputation.
Second-order effects
- Government cloud buyers can be expected to tighten procurement and audit requirements around storage configuration, pushing agencies toward managed controls and mandatory exposure scanning rather than self-configured buckets.
- Cloud providers gain a sales argument for default-private settings and configuration monitoring services, monetizing the exact failure mode their customers keep demonstrating.
Third-order effects
- If the pattern holds — from the airport backup drive through this disk image to the later DOD Azure database left passwordless for two weeks — the structural lesson is that human configuration error, not encryption or perimeter defense, is the dominant leak vector for sensitive data, shifting security spending toward automated posture management.
- Independent researcher discovery remains the de facto disclosure channel for these exposures, keeping pressure on both agencies and providers to build detection that does not depend on a stranger noticing.
The trend: Sensitive government and enterprise data keeps leaking through misconfigured cloud storage rather than breaches, making configuration error the recurring failure mode across AWS, Azure, and on-prem alike.