Any advice on how to safeguard against this?
If possible, use VPC endpoints and lock down the bucket to only allow access from them.
If possible, use VPC endpoints and lock down the bucket to only allow access from them.