Yes, an empty private Amazon S3 bucket really did accumulate about $1,300 in two days in a reported April 2024 incident. The bucket received nearly 100 million PUT requests after unrelated deployments used the same default bucket name. The name did not create the charge by itself; a widely copied placeholder caused misconfigured software to send traffic to the wrong account. AWS changed billing for some unauthorized errors in 2024, but naming, deletion, access-control and monitoring risks remain.
What happened in the reported $1,300 incident?
Developer Maciej Pocwierz reported that a private, empty S3 bucket generated approximately $1,300 in charges over two days, including nearly 100 million PUT requests in one day. Cybernews attributed the traffic to an open-source backup tool whose default configuration reportedly pointed many installations at the same placeholder bucket name: the Cybernews report.
Because the real bucket owner had registered that name, installations that were never reconfigured attempted to write to the owner’s endpoint. The account described the cause as widespread misconfiguration rather than proof of a single deliberate attacker. AWS reportedly canceled the bill as an exception; that outcome is not a guaranteed refund policy.
The lesson is narrower than “anyone can bankrupt you by knowing a bucket name.” An empty bucket can still receive enormous request volume, and some requests can be chargeable. The exact result depends on the operation, response code, caller’s account relationship, region and bucket configuration.
#1 Best Overall
Why an S3 bucket name is an infrastructure decision
For general-purpose S3 buckets, the name is part of a shared namespace across all accounts and Regions in an AWS partition. It appears in endpoints, logs, scripts and sometimes browser-facing configuration. AWS says names normally cannot be changed after creation, and the bucket’s Region cannot normally be changed either. See AWS’s naming rules.
The commercial AWS partition is aws; China, GovCloud and the European Sovereign Cloud use separate partitions. A name that is unavailable in one partition may therefore be available in another, but it is not a worldwide private label.
Names that attract accidental traffic
- Defaults copied from tutorials, Helm charts, Terraform examples, runbooks or backup tools.
- Predictable production labels such as
company-backupsorprod-assets, which are easy for scanners and scripts to guess. - Names associated with another company, product or domain, increasing the chance of copy-and-paste mistakes.
Deletion can create a second-owner problem
Deleting an unused bucket releases its name in the shared partition. Another account can later claim it, while old applications or clients continue sending requests to the former endpoint. That can cause broken applications, misrouted uploads, data disclosure or unexpected transfer charges. AWS recommends emptying and retaining an important bucket when continuity matters rather than deleting it casually.
Periods have compatibility costs
Periods are allowed in many names, but AWS recommends avoiding them except where static website hosting requires them. They can complicate virtual-hosted HTTPS certificate validation and are incompatible with S3 Transfer Acceleration.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesRank #2
Current S3 request billing: the response code matters
S3 charges for more than stored gigabytes. Request, retrieval, transfer, replication and management features can all contribute to a bill; see S3 pricing. A zero-object bucket is not necessarily a zero-activity bucket.
| Situation | Owner-charge treatment |
|---|---|
| Successful requests | Generally chargeable under S3 pricing. |
| Some 4XX responses | May be chargeable, depending on the error and configuration. |
External 403 AccessDenied |
Current AWS documentation says requests initiated outside the owner’s account or AWS Organization are not charged to the bucket owner. |
5XX responses such as 503 Slow Down |
Generally not billed as requests. |
| Requester Pays | The requester pays eligible request and download charges; the owner still pays storage. |
Check the live AWS table for the precise error and request path: Billing for Amazon S3 error responses. AWS announced the external-error change in 2024 at this announcement. Do not assume every unauthorized request is free—or that every failed request is billed.
Why the caller’s Region matters
Every bucket belongs to one Region. If a client omits the Region or uses the wrong endpoint, S3 can return a redirect or error. Retried requests and redirected paths add noise, complicate attribution and can create extra request activity. They do not automatically double a bill; the pricing effect depends on the operation and response.
Configure the Region explicitly in SDKs, CLI profiles, environment variables and infrastructure code. Treat a redirect as a deployment defect to fix, not as normal behavior.
Rank #3
Choose a name that is unique without leaking secrets
A practical pattern is:
<organization>-<application>-<environment>-<region>-<random-suffix>
For example: acme-doc-indexer-prod-us-east-1-7f3c91a2.
- Use a random suffix or GUID; do not copy a universal placeholder.
- Include environment and Region to reduce operator mistakes.
- Keep confidential information out of the name because it appears in URLs.
- Avoid periods unless static website hosting requires them.
- Create the bucket before dependent services deploy, then inject its name or ARN.
- Do not treat
head-bucketas a reservation; another deployment can win the race.
AWS also documents account-regional namespaces, using a prescribed format containing your chosen name, account ID, Region and an AWS suffix, such as customer-chosen-name-AWS-Account-ID-AWS-Region-an. This namespace is designed so another account cannot claim the same name; verify current API support before automating it.
What infrastructure code should enforce
- Generate a unique name or require an explicit, non-placeholder value.
- Create the bucket in the intended Region before configuring applications.
- Pass the created name or ARN to every dependent service.
- Fail safely on
BucketAlreadyExistsrather than silently selecting an unknown bucket. - Enable Block Public Access and least-privilege IAM.
- Add lifecycle rules suited to the workload.
- Configure cost and request monitoring before production traffic starts.
For a non-us-east-1 Region, a CLI creation example is:
aws s3api create-bucket
--bucket acme-doc-indexer-prod-us-west-2-7f3c91a2
--region us-west-2
--create-bucket-configuration LocationConstraint=us-west-2
For us-east-1, LocationConstraint handling differs; verify the behavior for the deployed AWS CLI version.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallPrivate does not mean harmless
Private access prevents unauthorized reads and writes from succeeding, but requests can still reach the endpoint. More importantly, a public-write or over-permissive policy can turn a naming mistake into storage, transfer and data-contamination costs. Attackers could upload malware or illegal content, or expose existing objects.
Apply the baseline control:
aws s3api put-public-access-block
--bucket acme-doc-indexer-prod-us-west-2-7f3c91a2
--public-access-block-configuration
BlockPublicAcls=true,IgnorePublicAcls=true,BlockPublicPolicy=true,RestrictPublicBuckets=true
Requester Pays is useful for shared datasets, not as a universal shield: the owner remains responsible for storage.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Monitoring that can catch an expensive mistake
AWS Budgets
Set account- and service-level thresholds with email or SNS alerts. AWS says budget monitoring is free; action-enabled budgets have separate pricing, with the first two free and additional ones listed at $0.10 per day on the current pricing page: AWS Budgets pricing. A budget is an alert and optional action, not an instant spending cap.
Cost Anomaly Detection
It uses machine-learning models and can notify by email or SNS, but AWS says detection may take up to 24 hours because billing data is delayed and new services need usage history. It does not monitor third-party AWS Marketplace products; use Budgets for those charges. See AWS Cost Anomaly Detection.
Free tools Windows power users keep installed
One-click scans. No signup required.
Best Value
S3 and CloudWatch request metrics
Daily storage metrics are provided at no additional charge. One-minute request metrics are CloudWatch custom metrics and therefore billed; AWS describes them as best effort, not a complete record of every request: S3 CloudWatch monitoring. Combine them with billing data, Cost and Usage Reports, CloudTrail where appropriate, server-access logs and application telemetry.
If S3 charges suddenly spike
- Do not immediately delete the bucket. Deletion can release the name and destroy evidence.
- Use Cost Explorer and billing details to isolate service, Region, usage type and operation.
- Check request metrics and logs for rates, object keys, caller identity and Regions.
- Review bucket policies, ACLs, Block Public Access, access points, replication and website settings.
- Search public code, templates and deployed configuration for the bucket name.
- Stop or correct misconfigured clients you control; restrict writes if data is arriving.
- Contact AWS Support promptly and preserve the bucket and logs.
- After containment, empty the bucket, add lifecycle controls and document whether retention is safer than deletion.
When other AWS services help
For public content, CloudFront with S3 Origin Access Control, signed URLs or signed cookies can keep the origin private, but caching, misses, viewer requests and transfer still cost money. Separate ingestion and delivery buckets when trust boundaries differ. CloudTrail is valuable for investigations, though high-volume S3 data-event logging needs its own cost model. Requester Pays suits public datasets where requesters can be identified and billed.
Deployment checklist
- Unique, non-placeholder name with a random suffix or supported account-regional namespace.
- Correct Region configured everywhere.
- Bucket created before clients deploy; conflicts fail safely.
- Block Public Access enabled and write permissions restricted.
- No secrets or personal data in the name.
- Budgets and anomaly alerts configured with their latency limits understood.
- Request monitoring enabled where its CloudWatch cost is justified.
- Deletion and name-retention rules documented.
The Bottom Line
The 2024 incident was real, but the enduring lesson is not that every bucket name is a financial trap. A copied global name can misroute enormous traffic; a deleted name can be reclaimed; and weak permissions can turn traffic into data and storage exposure. Use unique names, explicit Regions, strict access controls and layered billing monitoring—and preserve a suspect bucket until you understand the traffic.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




