- The incident: what happened and why it's relevant
- The mechanism of error: a public bucket is enough for everything
- The immediate impact on the hospitality and retail sectors
- What to do now: the operational checklist for SMEs
- The regulatory framework: GDPR and data breach notification
- A Milanese agency's view: cloud isn't automatically secure
- Perspectives: cloud security as a competitive advantage
In May 2026, a serious security incident affected the hospitality sector. The tech company managing a hotel check-in system configured its cloud storage as public. As a result, anyone could access over a million identity documents — passports and driver's licenses — without any password. The news, reported by TechCrunch , has reignited the debate on cloud configuration management in companies that handle sensitive data.
However, the problem doesn't just affect the hotel industry. Many Italian SMEs entrust their customer data to cloud storage — AWS S3, Azure Blob, Google Cloud Storage — without periodically checking access permissions. A bucket mistakenly configured as public, even temporarily, can expose thousands of records in minutes. Therefore, reviewing configurations isn't an optional activity: it's an operational priority.
At SHM Studio, we support SMEs in evaluating their digital infrastructure with a consulting approach that begins with analyzing concrete risks. Finally, remember that GDPR imposes significant penalties on organizations that do not adopt adequate technical measures to protect their customers' personal data. Acting before an incident is always less expensive than managing its consequences.
The incident: what happened and why it's relevant
In mid-May 2026, TechCrunch reported a data breach case that affected a hotel check-in system. The tech company responsible for the platform had configured its cloud storage with public visibility. In practice, anyone with the correct URL could download customer ID documents without authentication.
Over a million passports and driver's licenses were freely accessible. This is particularly sensitive data: combined with first name, last name, and date of birth, it can be used for identity theft, financial fraud, and unauthorized access to digital services.
Therefore, this episode isn't just a tech news item. It's a concrete signal that SMEs — even those far from the hospitality sector — should read carefully.
The mechanism of error: a public bucket is enough for everything
The main cloud providers — AWS, Microsoft Azure, Google Cloud — offer object storage like S3, Blob Storage, and Cloud Storage. These services are secure by default, but they require correct configuration by the user or the technical provider.
In this case, the problem was elementary: the bucket had been set to public access. No sophisticated vulnerability, no zero-day attack. Simply, a wrong checkbox — or one never checked — made data from a million people accessible.
In fact, according to Gartner, most cloud security incidents don't stem from provider system flaws, but from customer-side misconfigurations. This has been known for years, yet incidents continue to occur with alarming frequency.
On top of this, the problem worsens in organizations that outsource technical management to third-party providers. In these cases, configuration responsibility can become unclear, and periodic checks are often skipped.
The immediate impact on the hospitality and retail sectors
The hotel sector systematically collects guests' identity documents. However, it is not the only sector exposed. Retail, professional services, and e-commerce platforms also process personal data which, if exposed, can generate severe legal and reputational consequences.
In Italy, the GDPR — General Data Protection Regulation — requires organizations to adopt adequate technical and organizational measures. Consequently, a public cloud bucket exposing personal data constitutes a direct violation of Article 32, concerning the security of processing.
The penalties provided can reach up to 4% of global annual turnover, or 20 million euros. Furthermore, reputational damage — difficult to quantify — can erode customer trust in a lasting way. For an SME with tight margins, such an incident can have existential consequences.
What to do now: the operational checklist for SMEs
Responding to this type of incident doesn't require extraordinary investments. It requires method and attention to existing configurations. Below are the priority actions that every SME should check immediately.
- Audit access permissions: verify that all cloud buckets — AWS S3, Azure Blob, Google Cloud Storage — are configured with private access. No sensitive data should be publicly accessible without authentication.
- Enable blocking of public access: AWS, Azure, and Google offer global public access blocking settings. These features should be active by default in all production environments.
- Review IAM policies: Identity and Access Management policies must follow the principle of least privilege. Each user or service should only access the resources strictly necessary.
- Continuous monitoring: tools like AWS Config, Azure Security Center, or Google Security Command Center allow for the automatic detection of non-compliant configurations. Therefore, it's advisable to enable them and set up real-time alerts.
- Contracts with third-party suppliers: if cloud management is entrusted to an external partner, the contract must include explicit clauses on the responsibility for security configurations and the methods for periodic auditing.
Similarly, it's useful to plan a periodic penetration test focused on cloud configurations, at least once a year or after any significant infrastructure change.
The regulatory framework: GDPR and data breach notification
In case of personal data breach, GDPR imposes precise obligations. First of all, the organization must notify the Personal Data Protection Authority within 72 hours of discovering the incident. Subsequently, if the breach involves a high risk for the rights of the data subjects, it is also necessary to communicate it to the people involved.
However, many SMEs lack internal procedures to manage these scenarios. The absence of an incident response plan further exacerbates the situation in case of a breach.
Therefore, regulatory compliance is not just a legal matter. It's also a competitive element: B2B and retail customers increasingly choose suppliers who demonstrate data management maturity. As highlighted by Harvard Business Review , companies that suffer public breaches experience an average drop of 7.5% in stock value in the days following the announcement.
A Milanese agency's view: cloud isn't automatically secure
We at SHM Studio we often observe a widespread belief among Italian SMEs: relying on a large cloud provider means being safe. This perception is partially correct, but deeply misleading.
Cloud providers ensure the security of their infrastructure. However, configuring the environments remains the responsibility of the customer or their technical provider. This is the so-called shared responsibility model — shared responsibility model — which AWS, Azure, and Google explicitly document in their policies.
Therefore, the problem is not technology. It's governance. SMEs that lack internal technical oversight tend to completely delegate cloud management to external providers, without planning for periodic audits or independent checks. This approach exposes them to concrete risks, as the analyzed case demonstrates.
In particular, for companies that collect identity documents, payment data, or health information, the level of attention must be proportionally higher. The applied artificial intelligence services and the digital marketing strategies that we manage for our clients are always based on a verified and compliant data infrastructure.
Perspectives: cloud security as a competitive advantage
Looking ahead to the next 12-24 months, regulatory pressure on personal data processing is set to increase. In Europe, the Data Act and the AI Act will introduce further requirements for organizations processing data at scale. Additionally, B2B buyers are including cybersecurity among their supplier selection criteria.
Consequently, SMEs that invest today in the correct configuration of their cloud infrastructures are not just avoiding penalties. They are building a measurable competitive advantage. As the McKinsey Global Institute highlights, cyber resilience is now an indicator of business reliability perceived by the markets.
Finally, let's remember that security isn't a project with an end date. It's an ongoing process that requires regular reviews, policy updates, and staff training. The web solutions and the SEO strategies that we develop in SHM Studio are always integrated with an assessment of the client's overall digital maturity, including secure data management.
To learn more about how to structure a cloud security approach suitable for Italian SMEs, you can consult our resources on Blog or contact us directly for a preliminary assessment.
Related articles
Discover more articles exploring similar topics, selected to offer you a more complete and stimulating perspective. Each piece of content is carefully chosen to enrich your experience.