EY’s 4TB Oopsie: Accounting Giant’s Data Left Out for Trick-or-Treaters on Azure!
Ernst & Young (EY) accidentally left a massive 4TB SQL Server backup publicly accessible on Microsoft Azure. Neo Security’s lead researcher discovered the unencrypted data dump while doing some light internet sleuthing. EY quickly fixed the issue, but not before everyone wondered how many digital nosy parkers had already taken a peek.

Hot Take:
In a plot twist worthy of a cybersecurity thriller, Ernst & Young’s 4TB SQL server backup decided to celebrate Halloween by going as a “Public Database!” With countless actors in the audience, the only thing more exposed than EY’s data was its reputation. But hey, at least the server wasn’t dressed as a clown.
Key Points:
- EY’s 4TB SQL server backup was found publicly accessible on Microsoft Azure.
- Neo Security discovered the file during a routine scan, identifying it as unencrypted and potentially sensitive.
- The backup was linked to EY through DNS SOA lookups and merger documents.
- Despite 15 attempts, EY was finally informed and quickly remediated the issue.
- The incident underscores the high risks of cloud exposure and the necessity for continuous monitoring.
Already a member? Log in here
