At 10:58, a terraform apply run by svc-terraform changed the ACL on hr-records-prod (S3 · us-east-1) from private to public-read. The bucket contains 4.2 GB of HR records including SSNs and salary data. AWS Macie detected the ACL change within 38 seconds and the AI automatically reverted the bucket to private and blocked public access at the account level. The terraform state file has been flagged — an infrastructure review is recommended to prevent recurrence. No data was accessed during the 38-second exposure window (CloudTrail shows zero GET requests).