Verizon Customer Records Exposed via a Vendor's S3 Bucket (July 2017)
Retrospective: this article looks back at events from July 2017, written in 2026 with the benefit of hindsight.
In July 2017, UpGuard researchers reported that records belonging to millions of Verizon customers were sitting in a publicly accessible Amazon S3 bucket. The bucket was controlled by NICE Systems, a vendor that handled customer service call data for Verizon.
What was exposed
Customer names, addresses, phone numbers and, in some cases, account PINs used to verify identity with customer service. Verizon said about six million customers were affected; researchers estimated more.
How it happened
The bucket was configured to allow public access. NICE had set it up for a legitimate business purpose and had not restricted it. As with other 2017 S3 incidents, nothing was "hacked" — the data was simply available to anyone who found the bucket.
Why it mattered
PINs are particularly sensitive: they are used to authenticate customers to call-center agents, the very process attackers abuse to hijack phone numbers through SIM swapping. Exposed PINs meant exposed accounts, not just exposed contact details.
Lessons in hindsight
- Third parties need the same cloud controls you do. Contracts should require private-by-default storage and monitoring.
- Bucket policies need least privilege. Grant access to specific roles or services, not broadly.
- Authentication secrets do not belong next to customer data, and should be hashed or encrypted if stored at all.
- Monitoring by the data owner — not just the vendor — would have caught it sooner.
Verizon's exposure added to pressure on AWS to make public access harder. Within 18 months, S3 Block Public Access was available; within six years, it was on by default for new buckets.