<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Cloud Storage Misconfiguration on Security Blueprints</title>
    <link>https://securityblueprints.io/tags/cloud-storage-misconfiguration/</link>
    <description>Recent content in Cloud Storage Misconfiguration on Security Blueprints</description>
    <generator>Hugo</generator>
    <language>en</language>
    <managingEditor>user@example.com (Niels Provos)</managingEditor>
    <webMaster>user@example.com (Niels Provos)</webMaster>
    <copyright>Security Blueprints, LLC</copyright>
    <lastBuildDate>Sun, 06 Sep 2026 23:57:44 +0000</lastBuildDate>
    <atom:link href="https://securityblueprints.io/tags/cloud-storage-misconfiguration/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Real Estate Wealth Network Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/real-estate-wealth-network-data-breach/</link>
      <pubDate>Fri, 01 Dec 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/real-estate-wealth-network-data-breach/</guid>
      <description>Executive Summary The Real Estate Wealth Network (REWN) data breach in December 2023 involved the unauthorized exposure of over 1.5 billion records due to a cloud misconfiguration. This extensive breach was discovered by cybersecurity researcher Jeremiah Fowler on December 20, 2023. Public disclosure followed on December 26, 2023. The breach predominantly exposed personal and property information, posing significant risks such as identity theft and financial fraud.&#xA;Key Details Breach Date: December 2023 Discovery Date: December 20, 2023 Severity: Exposure of personal data including Social Security numbers and property ownership details Root Cause: Cloud configuration error, an internal oversight Impact Affected Individuals: Millions, including both private citizens and high-profile figures Consequences: Risks of identity theft, financial fraud, harassment, and privacy invasion Response REWN secured the database after the breach was disclosed and plans to conduct a forensic audit to assess potential unauthorized access.</description>
    </item>
    <item>
      <title>Pegasus Airlines Data Exposure</title>
      <link>https://securityblueprints.io/data-breaches/pegasus-airlines-data-exposure/</link>
      <pubDate>Tue, 01 Mar 2022 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/pegasus-airlines-data-exposure/</guid>
      <description>Executive Summary Incident Overview In March 2022, Pegasus Airlines faced a data exposure due to a misconfiguration in an AWS S3 bucket by a system administrator. This incident led to the exposure of approximately 23 million files, containing Personally Identifiable Information (PII) and critical operational data (source ).&#xA;Severity of Impact The breach involved 6.5 terabytes of sensitive data, including sensitive operational information, crew identification details, plaintext passwords, secret keys, insurance documents, and safety guidelines.</description>
    </item>
    <item>
      <title>Capital One Data Breach 2019</title>
      <link>https://securityblueprints.io/data-breaches/capital-one-data-breach-2019/</link>
      <pubDate>Wed, 17 Jul 2019 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/capital-one-data-breach-2019/</guid>
      <description>Executive Summary In July 2019, Capital One experienced a significant data breach that compromised over 100 million customer records. This breach occurred due to a server-side request forgery (SSRF) exploiting a misconfigured Web Application Firewall (WAF) in their systems. The attack was orchestrated by Paige A. Thompson, a former software engineer at Amazon Web Services (AWS), leveraging insider knowledge and scanning for vulnerabilities using the misconfigured AWS resources.&#xA;Key Dates Attack Period: March 22-23, 2019 Discovery Date: July 19, 2019 Public Disclosure: July 29, 2019 Severity of Impact This breach ranks among the largest in history, affecting approximately 100 million individuals in the United States and around 6 million in Canada, approximately 106 million individuals combined.</description>
    </item>
    <item>
      <title>Facebook Data Breach 2019</title>
      <link>https://securityblueprints.io/data-breaches/facebook-data-breach-2019/</link>
      <pubDate>Mon, 01 Apr 2019 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/facebook-data-breach-2019/</guid>
      <description>Executive Summary In April 2019, a significant data breach affected Facebook, exposing the personal information of over 530 million users across 106 countries. The breach involved the improper access and sharing of two datasets, revealing sensitive information such as phone numbers, account names, Facebook ID numbers, and email addresses. The exposure occurred due to the misuse of Facebook&amp;rsquo;s &amp;lsquo;contact importer&amp;rsquo; feature and improperly secured third-party applications hosted on Amazon Web Services (AWS) servers.</description>
    </item>
    <item>
      <title>Deep Root Analytics Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/deep-root-analytics-data-breach/</link>
      <pubDate>Mon, 12 Jun 2017 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/deep-root-analytics-data-breach/</guid>
      <description>Executive Summary In 2017, a data breach at Deep Root Analytics exposed the sensitive information of approximately 198 million U.S. voters. This information, linked to the Republican National Committee (RNC), was leaked due to a misconfigured Amazon Web Services (AWS) S3 bucket, which lacked adequate security settings. The breach included personal information such as names, addresses, birth dates, phone numbers, political affiliations, and predictive modeling data on ethnicities and religious orientations.</description>
    </item>
    <item>
      <title>2014 Uber Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/2014-uber-data-breach/</link>
      <pubDate>Mon, 12 May 2014 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/2014-uber-data-breach/</guid>
      <description>Executive Summary In 2014, Uber experienced a significant data breach, where approximately 50,000 consumers&amp;rsquo; sensitive information, particularly names and driver&amp;rsquo;s license numbers, was accessed without authorization. This incident arose from the mishandling of an unencrypted Amazon Web Services (AWS) access key that was inadvertently published on GitHub, thereby allowing attackers unauthorized system access. (source , source )&#xA;Key Dates:&#xA;May 12, 2014: Attackers gained access to Uber&amp;rsquo;s AWS account by exploiting a publicly exposed AWS access key on GitHub.</description>
    </item>
  </channel>
</rss>
