AWSIncident TeardownsRetrospectives

198 Million Voter Records in an Open S3 Bucket (June 2017): Anatomy of a Misconfiguration

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from June 2017, written in 2026 with the benefit of hindsight.

In June 2017, researcher Chris Vickery of UpGuard found an Amazon S3 bucket containing personal data on about 198 million American voters. It belonged to Deep Root Analytics, a data firm working for the Republican National Committee. Anyone who knew the bucket name could download the data — no password required.

What was exposed

Names, dates of birth, home addresses, phone numbers, voter registration details and modeled data on likely political views and positions on issues. It was one of the largest exposures of voter data ever recorded.

How it happened

This was not a hack. The bucket had been configured to allow public access. S3 buckets were private by default, but a single policy or access control list change could open them to the world, and in 2017 there were few guard rails or warnings to stop it.

Why it mattered

The incident was part of a wave of S3 exposures in 2017 that included Verizon, Dow Jones, Accenture and US defense contractors. Each followed the same pattern: a vendor or team stored sensitive data in S3, misconfigured access, and a researcher found it with simple scanning tools.

Lessons in hindsight

  • Data held by vendors is still your data. The RNC's reputation suffered for a contractor's mistake.
  • Misconfiguration, not vulnerability, is the leading cause of cloud data exposure.
  • Defaults and guard rails matter. AWS later added account-level Block Public Access (2018) and made it the default for new buckets (2023).
  • Continuous monitoring finds problems before researchers — or attackers — do.

The 2017 S3 leaks are the reason "check for public buckets" is now the first item in every cloud security assessment.

s3 bucket data leakRNC voter data S32017

More on this story