AzureCIO BriefingsRetrospectives

CIO Brief: Storage Misconfiguration Is a Cloud-Agnostic Problem

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from October 2022, written in 2026 with the benefit of hindsight.

The short version: In 2022, researchers reported that a misconfigured Microsoft storage location exposed business documents involving Microsoft's customers. Microsoft disputed the scale but confirmed the misconfiguration. Storage misconfiguration happens in every cloud and to every provider.

Why it's the same story everywhere

Amazon S3 buckets, Azure Blob containers and Google Cloud Storage all have settings that can make data public. Every major cloud provider has had customer and internal incidents caused by them. The fix is the same: prevent public access by default, and monitor for exceptions.

The business impact

  • Exposure of contracts, pricing and customer communications.
  • Competitive harm if business documents leak.
  • Disputes and uncertainty about what was exposed.

Questions to ask your team

  • In every cloud we use, is public storage access blocked by default?
  • Can anyone change that, or is it enforced centrally?
  • How quickly would we know if storage became public?
  • Do we use identity-based access instead of shared keys and links?

What good looks like

Public access blocked by policy in every cloud, identity-based access to storage, monitoring for exposure, and a short list of documented exceptions.

The decision

Ask for a single report covering storage exposure across all your cloud providers. If you use more than one cloud, the gaps are often in the one you use least.

bluebleed impactBlueBleed2022

More on this story