‘Secure’ Backup Company Leaks 135 Million Records Online After Misconfiguration – Experts Insight

A company claiming to provide “the world’s most secure online backup” leaked metadata and customer information in over 135 million records after misconfiguring an online database, Infosecurity has learned.

The trove included PII such as names, emails, phone numbers, business details (for corporate customers) and account usernames.

The team at vpnMentor discovered the privacy snafu as part of its ongoing web mapping project that has already uncovered major cloud data leaks at brands including Decathlon, PhotoSquared and Yves Rocher.

“The exposed database contained over 135 million records, totalling almost 70GB of metadata related to user accounts on SOS Online Backup. This included structural, reference, descriptive, and administrative metadata covering many aspects of SOS Online Backup’s cloud services,” vpnMentor explained.


EXPERTS COMMENTS
Tim Erlin, VP of Product Management and Strategy ,  Tripwire
April 02, 2020
A misconfiguration can be like doing the attacker’s work for them.
A misconfiguration can be like doing the attacker’s work for them. No one has to break in, if the front door is left open. Organizations are often very aware of security vulnerabilities, but continuously scanning for misconfigurations is just as important. Environments change, and change can result in data being mistakenly exposed. If you’re scanning for vulnerabilities, but not addressing th ....
[Read More >>]

If you are an expert on this topic:

Submit Your Expert Comments


In this article