Early Bird Offer !Pay Just 10%Get full Cloud Lens AI access for a limited timeClaim Now
Home/Case Studies/CloudFront Origin Access Misconfiguration Exposing Private S3 Content
Security · AWS

CloudFront Origin Access Misconfiguration Exposing Private S3 Content

MG
MediaStream Global
Digital Media · 85 employees · Global CloudFront CDN
CloudFront Origin Access Misconfiguration Exposing Private S3 Content
100%
public leak resolved
$500–700
Monthly savings identified
74 → 94
Security score improvement
< 5 min
From upload to full report

A media company stored premium video content in a private Amazon S3 bucket. AWS CloudFront was configured to securely deliver videos using signed URLs. The architecture required that users access content exclusively through CloudFront while the S3 bucket remained inaccessible from the internet.

During a migration from Origin Access Identity (OAI) to Origin Access Control (OAC), an administrator updated the CloudFront distribution but forgot to remove a legacy S3 bucket policy that temporarily allowed public read access for testing. The CloudFront distribution continued functioning normally, so no operational issues were detected.

Several weeks later, a security audit revealed that search engines had indexed direct S3 object URLs. Anyone possessing the S3 object URL could download premium videos without CloudFront authentication or signed URLs. Since requests bypassed CloudFront entirely, download activity was invisible in CloudFront logs and access controls.

The security team immediately blocked public bucket access using S3 Block Public Access, replaced the bucket policy with an OAC-restricted policy, rotated signed URL keys, and requested removal of indexed URLs from search engines. CloudTrail and S3 server access logs were analyzed to determine the extent of unauthorized downloads.

Root Cause

  • Misconfigured S3 bucket policy during OAI-to-OAC migration.
  • Public bucket access left enabled after testing.
  • Lack of continuous configuration compliance monitoring.

Business Impact

  • Unauthorized access to premium digital content.
  • Revenue loss due to content piracy.
  • Increased legal and compliance efforts.
  • Damage to brand reputation.

Lessons Learned

  • Always enable S3 Block Public Access for private content.
  • Prefer Origin Access Control (OAC) over legacy OAI for new deployments.
  • Continuously monitor bucket policies using AWS Config and Amazon GuardDuty.
  • Periodically audit CloudFront origins to ensure S3 objects cannot be accessed directly.
  • Include storage access validation in every production deployment checklist.
Cost Assessment
Parses AWS Cost and Usage Reports to attribute every dollar to a service, environment, and owning team, then ranks recoverable spend by dollar impact and implementation effort.
Security Posture Score
Evaluates configuration and exposure signals across accounts to produce a single comparable score, highlighting findings where cost risk and security risk overlap.
Board-Ready Reporting
Generates a narrative assessment with an executive summary, trend context, and prioritised recommendations, formatted for finance and leadership audiences, not engineers.
Privacy-First Architecture
Works from billing exports alone. No agents, no cross-account roles, and no access to production workloads or customer data at any point in the assessment.

Key outcomes

  • 100% reduction in targeted AWS processing spend within weeks of deployment.
  • Clear visibility into VPC endpoint and data transfer costs without requiring agents.
  • Security score improved by retiring exposed and unmonitored egress routes.
  • Board-ready reporting turnaround reduced to minutes with automated exports.

Cloud Lens AI didn't just find the savings, it settled the argument. For the first time, engineering and finance were looking at the same number and agreeing on what to do about it.

Cloud Architecture Leadership
#Security#AWS#CloudCost#FinOps#CaseStudy

More case studies

See what your bill is hiding

Upload your AWS bills and get a board-ready cost and security assessment in minutes.

Get Started