9% of public cloud storage contains sensitive data

Tenable®, a company specializing in exposure management, has released its 2025 Cloud Security Risk Report, revealing that 9% of publicly accessible cloud storage contains sensitive data, of which 97% is classified as restricted or confidential.
This level of exposure significantly increases the risk of exploitation—particularly when combined with misconfigurations or embedded secrets.
Main Vulnerabilities Identified.
The report highlights that cloud environments face elevated risks due to the exposure of sensitive data, misconfigurations, software vulnerabilities, and poor management of secrets such as passwords, API keys, and credentials.
It also offers in-depth analysis of critical security challenges impacting data, identity, workloads, and artificial intelligence (AI) resources, along with practical strategies to mitigate these threats.
Key findings include:
1) More than half of organizations (54%) store at least one secret directly in the task definitions of Amazon Web Services (AWS) Elastic Container Service (ECS), creating a direct path for attackers. Similar issues were observed in Google Cloud Platform (GCP) Cloud Run (52%) and Microsoft Azure Logic Apps (31%). In addition, 3.5% of all AWS Elastic Compute Cloud (EC2) instances contain secrets in user data—a significant risk given the widespread use of EC2.
2) Cloud workload security has improved, yet the so-called “toxic cloud triad” persists: a publicly accessible workload that is both critically vulnerable and highly privileged. The presence of this dangerous combination has decreased from 38% to 29%, but still represents a significant and recurring threat.
3) The use of Identity Providers (IdPs) does not fully eliminate risk. While 83% of organizations using AWS implement IdP best practices, issues such as excessive permissions, overly permissive defaults, and persistent privileges continue to expose them to identity-based threats.
Ari Eitan, Senior Director of Cloud Security Research at Tenable, provides the following analysis:
“Despite the security incidents we’ve witnessed in recent years, organizations continue to leave critical assets—ranging from sensitive data to secrets—exposed in the cloud due to avoidable misconfigurations. Attackers often find an easy path: exploit public access, steal embedded secrets, or abuse over-privileged identities. To close these gaps, security teams need full visibility into their environments and the ability to prioritize and automate remediation before threats escalate. Cloud risk management must be continuous and proactive—not reactive patching.”
Report Origin and Scope.
The report is based on telemetry collected by the Tenable Cloud Research team, analyzing workloads across various enterprise and public cloud environments between October 2024 and March 2025.
To download the full report, visit:
https://www.tenable.com/cyber-exposure/tenable-cloud-security-risk-report-2025

