INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Pentagon Leaked Internet Surveillance Archive Exposes Widespread Online Monitoring
| 2025-07-10 08:09 DATA BREACH
Executive Summary
AI-generated
A massive data breach occurred on September 6th, 2017, when three publicly downloadable cloud-based storage servers exposed a vast amount of data collected by CENTCOM and PACOM, two Pentagon unified combatant commands. The repositories contained billions of public internet posts and news commentary scraped from individuals in the US and around the world over an 8-year period, including content captured from social media sites like Facebook featuring multiple languages. Approximately 1.8 billion posts were estimated to be part of the exposed data, with many appearing benign yet raising serious concerns about Pentagon surveillance against US citizens. The attack worked by exploiting unsecured cloud storage servers that allowed any AWS global authenticated user to browse and download contents; an investigation revealed a defunct private-sector government contractor named VendorX was involved in creating these data stores.
Technical Mitigations AI-generated
• Block or hunt for AWS global authenticated users with free sign-up capabilities.
• Patch VendorX software vulnerabilities, as indicated by the presence of a "Settings" table in the bucket "centcom-backup".
• Detect and address CSTAR cyber risk scores below 950, such as CENTCOM's score of 542.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
co•••••.the
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
Intelligence Sources
Upguard
2025-07-10