EY’s 4TB Oopsie: Accounting Giant’s Data Left Out for Trick-or-Treaters on Azure!

Ernst & Young (EY) accidentally left a massive 4TB SQL Server backup publicly accessible on Microsoft Azure. Neo Security’s lead researcher discovered the unencrypted data dump while doing some light internet sleuthing. EY quickly fixed the issue, but not before everyone wondered how many digital nosy parkers had already taken a peek.

Pro Dashboard

Hot Take:

In a plot twist worthy of a cybersecurity thriller, Ernst & Young’s 4TB SQL server backup decided to celebrate Halloween by going as a “Public Database!” With countless actors in the audience, the only thing more exposed than EY’s data was its reputation. But hey, at least the server wasn’t dressed as a clown.

Key Points:

  • EY’s 4TB SQL server backup was found publicly accessible on Microsoft Azure.
  • Neo Security discovered the file during a routine scan, identifying it as unencrypted and potentially sensitive.
  • The backup was linked to EY through DNS SOA lookups and merger documents.
  • Despite 15 attempts, EY was finally informed and quickly remediated the issue.
  • The incident underscores the high risks of cloud exposure and the necessity for continuous monitoring.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?