A study by website security firm Sansec found that about 12% of online stores leave their backups in public folders due to human error or negligence.
Online security is a critical issue that businesses need to address, especially with the growth of e-commerce sites.
See also: Medusa botnet returns as Mirai-based variant

The study analyzed over 2,000 stores of various sizes and found that 250 of them have exposed ZIP, SQL and TAR files in shared online folders that could be easily accessed by anyone. These files contain critical data, such as database passwords, hidden administrator URLs, internal API keys and customer personally identifiable information (PII).
The Sansec report reveals that the ongoing activity by attackers launching automated scans to search for these backups is a cause for concern.

Threat actors often try different combinations of backup names based on page names and public DNS data , such as “/db/staging-SITENAME.zip” . These attacks are cheap and do not affect the efficiency of the targeted store, which makes it possible for threat actors to conduct these scans for weeks until they find a backup. Exposed backups can be used to gain control of the store, blackmail sellers, and steal customer payments. Attackers can gain access to the site and steal data or perform destructive attacks if they find administrator credentials , master database passwords, or staff accounts. The report also highlights that cyber attackers are well aware of the existence of these exposed backups, and several different IP addresses are observed for such attacks. See also: CISA: Provides recovery script for victims of ESXiArgs ransomware

To prevent these types of breaches, Sansec urges online store owners to regularly check their sites for exposed data and backups.
If an exposed backup is found, immediate action should be taken, such as resetting admin and database passwords, enabling 2FA on all staff accounts, and checking web server logs to see if the backup has fallen into the hands of a third party.
Web admins should configure their web servers to restrict access to archive files, while those using the Adobe Commerce platform should use the “immutable storage” feature .Businesses
should take website security seriously and ensure they take all necessary measures to protect sensitive data.
Exposed backups can have serious consequences, and it is important to be proactive in protecting your business and your customers’ data.
Information source: bleepingcomputer.com
