HomeAlertsCASE-5501
Back to Alerts

S3 bucket hr-records-prod ACL changed to public-read by terraform apply

CriticalAI ReadyMatters AI already took action automatically. Review and confirm, or override.User: terraform@acme-corp.comDetected: 12 min ago
True positiveAutomated containment applied

At 10:58, a terraform apply run by svc-terraform changed the ACL on hr-records-prod (S3 · us-east-1) from private to public-read. The bucket contains 4.2 GB of HR records including SSNs and salary data. AWS Macie detected the ACL change within 38 seconds and the AI automatically reverted the bucket to private and blocked public access at the account level. The terraform state file has been flagged — an infrastructure review is recommended to prevent recurrence. No data was accessed during the 38-second exposure window (CloudTrail shows zero GET requests).

WHY FLAGGED
hr-records-prod ACL changed to public-read — bucket contains Restricted PII (SSN, salary)
Change made by svc-terraform (CI/CD) — not a human, no change-approval ticket
38-second exposure window before auto-remediation — CloudTrail shows zero external GETs
Alert Info
Assigned to
Unassigned
Alert ID
CASE-5501
AI Investigation
Automated containment applied
Alerts
1 linked
Detection
Datastore types
S3
Policy
Risk type
Configuration Drift
User
User
svc-terraform (CI/CD)terraform@acme-corp.com
Department
Engineering
Employment
Service account
Ask Matters AI
Hi, I'm Matters AI. Ask me about your alerts, cases, or policies.