AWS to Disable S3 SSE-C Encryption by Default (April 2026)
AWS published advance notice that starting April 6, 2026, SSE-C (Server-Side Encryption with Customer-Provided Keys) will be disabled by default on all new S3 buckets and existing buckets without SSE-C data. The Cloud Security Alliance noted this also closes a ransomware attack vector where attackers re-encrypt objects with their own keys.