Stolen Credentials, Not Hacking, Now Drive Most Cloud Storage Breaches
Cloud storage security is increasingly undermined by identity-based attacks rather than infrastructure exploits, with stolen credentials serving as the initial access vector in roughly 22% of confirmed breaches according to Verizon's 2025 Data Breach Investigations Report. Automated tools continuously test stolen login combinations against cloud services, a technique known as credential stuffing, making reused passwords a critical liability. Researchers analyzing a 19-billion-password leak found reused or duplicated credentials were widespread, lowering the bar for attackers significantly. Configuration errors compound the risk, as misconfigured public-facing storage buckets can expose sensitive data without requiring any login at all. Security experts emphasize that under the cloud shared responsibility model, customers — not providers — are accountable for access controls, making multi-factor authentication and proper permissions essential defenses.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in