A critical cloud storage attack technique dubbed “bucket hijacking” a method that enables threat actors to silently redirect an organization’s active cloud data streams, including audit logs and telemetry, into attacker-controlled external storage buckets across major cloud platforms.
The technique has been confirmed to affect Google Cloud, Amazon Web Services (AWS), and Microsoft Azure, with all three providers notified through responsible disclosure.
While no real-world threat actor has been observed exploiting this technique yet, researchers warn that detection would be extremely difficult once deployed.
The attack exploits a fundamental architectural flaw rooted in the global uniqueness of cloud storage bucket names. Because no two users can register an identical bucket name within a provider’s namespace, the identity of a destination storage bucket is tied to its name alone, not to a specific account owner.
An attacker who compromises a cloud environment and gains bucket deletion permissions can execute the attack in a straightforward sequence:
The attack is particularly dangerous because it is self-sustaining. Once the hijack is complete, the legitimate sink or replication configuration continues to appear valid upon inspection, generating no obvious error states and triggering no native alerts. Logs, metrics, and sensitive telemetry flow silently into the attacker’s environment indefinitely.
Unit 42 successfully simulated bucket hijacking across multiple services on each major provider:
storage.buckets.delete and storage.objects.deleteResearchers highlighted that broad storage administration roles commonly assigned in enterprise environments dramatically increase exposure.
In Google Cloud, the standard Storage Admin role grants storage.buckets.delete by default, bypassing the more restrictive logging.sinks.update permission that would be required to legitimately reconfigure a data stream. This effectively allows attackers to reroute data streams without ever touching stream configurations directly.
Unit 42 recommends a two-pronged defense strategy combining least-privilege access controls and proactive monitoring:
storage.buckets.delete, DeleteBucket, Microsoft.Storage/storageAccounts/delete) to the minimum required administrative rolesUnit 42 highlighted that this technique is not limited to the three providers tested. Any cloud platform relying on globally unique, statically named storage resources for data stream routing could be vulnerable to the same methodology.
The research reinforces that shared design philosophies across cloud providers mean a flaw discovered in one ecosystem can serve as a direct blueprint for exploiting another, a critical reminder for security teams managing multi-cloud environments.
🔒 CISO / Security Leader: Your Next Breach May Not Have a Face: Join the “Ghost in the Machine” LIVE webinar with ISC2
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…