GUIDE

How to find public S3 buckets.

August 27, 2026

Public usually means two things

An S3 bucket is public if anyone on the internet can list or read objects — via a bucket ACL grant to AllUsers / AuthenticatedUsers, or a bucket policy with "Principal": "*" and an allow. AWS’s Block Public Access (four flags, at the account and/or bucket) is what stops that from happening by accident.

A bucket can also be “not public right now” but unprotected: Public Access Block is off, so the next IAM change or a copied ACL makes it public. That is the finding most scanners treat as medium; an actually-public bucket is critical.

Find it yourself

Account-level block (do this first if you do not host a public site from S3):

aws s3control get-public-access-block --account-id <12-digit>

Per bucket:

aws s3api list-buckets --query 'Buckets[].Name' --output text
aws s3api get-public-access-block --bucket <name>
aws s3api get-bucket-policy-status --bucket <name>
aws s3api get-bucket-acl --bucket <name>

PolicyStatus.IsPublic already accounts for Block Public Access. ACL grants do not — if IgnorePublicAcls is on, a leftover public ACL is inert. Turn all four flags on unless you have a documented reason not to:

aws s3api put-public-access-block --bucket <name> \
  --public-access-block-configuration \
  BlockPublicAcls=true,IgnorePublicAcls=true,BlockPublicPolicy=true,RestrictPublicBuckets=true

Console: S3 → the bucket → Permissions → Block public access. Same four toggles exist at the account level (S3 → Block Public Access settings for this account). Account-level on is the cheapest insurance for every future bucket.

What is not this problem

  • CloudFront in front of a private bucket with an origin access control — that can be fine.
  • A static website you meant to publish. Then keep Block Public Access off only on that bucket, and lock the policy to s3:GetObject on the site prefix, not s3:* on *.
  • Objects that are public because someone set an object ACL years ago. Bucket-level Block Public Access with IgnorePublicAcls covers that; object ACLs are otherwise easy to miss.

Where PostureRadar fits

PostureRadar lists every bucket, checks ACLs, policy status, and Block Public Access (bucket and account), and emails you. Public buckets come through as critical; missing Block Public Access without a current public grant is medium. It's $39 per account per month, weekly. The remediation guidance is the same four flags above.

Related: Stale IAM access keys · Why AWS Config gets expensive · Security Hub finding noise