Cap1 hack - someone was able to execute arbitrary GETs on an ec2 machine, use that machine's IAM role to then list and sync s3 buckets.
So... s3 perms were okay
using IAM roles, not plaintext keys
But the IAM role had too many rights
https://blog.cloudsploit.com/a-technical-analysis-of-the-capital-one-hack-a9b43d7c8aea?gi=63a518330b97
Post
August 4, 2019