HomeSecurityEY Data Leak – SQL Server backup file exposed

EY Data Leak – Exposed SQL Server backup file

A massive SQL Server backup file (4TB), belonging to global accounting giant Ernst & Young (EY), was publicly accessible on Microsoft Azure.

EY SQL Server backup file data leak

The report, uncovered by cybersecurity firm Neo Security during a regular asset mapping exercise, highlights how even well-resourced organizations can inadvertently leave sensitive data vulnerable to automated web scanners.

Neo Security's lead researcher discovered the file while examining passive network traffic with low-level tools. A simple HEAD request, intended to extract metadata without downloading content, revealed the impressive size of the exposed file: 4 terabytes of data, equivalent to millions of documents or an entire library of information.

Apparently, it was a SQL Server backup (.BAK format), which usually contains complete database dumps, including schemas, user data , and, most importantly, embedded secrets such as API keys, credentials, and authentication tokens.

See also: LG Uplus: Cybersecurity incident for the telecommunications provider

EY Data Leak – Exposed SQL Server backup file

File discovery and connection with Ernst & Young (EY)

Initial searches in Azure Blob Storage did not immediately yield ownership evidence, but deeper exploration revealed merger documents in a European language, translated with tools like DeepL, indicating a 2020 acquisition. A critical DNS SOA record lookup linked the domain to ey.com, confirming EY’s involvement. To avoid legal pitfalls, the team downloaded only the first 1,000 bytes of the file, revealing an unmistakable “magic bytes” signature for an unencrypted backup .

This wasn’t a theoretical risk. Neo Security based its findings on real-world incidents, recalling a fintech breach that resulted from the brief exposure of a similar .BAK file for just five minutes. In that case, attackers exploited the brief window to extract personal information and credentials and deploy ransomware, disrupting the company’s operations.

See also: Hackers claim to have breached HSBC USA customer records

With today’s botnets scanning the entire IPv4 address space in minutes, such reports inevitably lead to breaches. Neo Security stopped further investigation and tried to responsibly notify the company over the weekend. Finally, it was able to connect with EY’s CSIRT, via LinkedIn, after 15 attempts.

EY responded quickly and professionally, assessing and resolving the issue within a week. This is important in an industry often plagued by denial or delays.

EY Data Leak – Exposed SQL Server backup file

However, the incident highlights systemic vulnerabilities in the cloud. Azure's ease of database export can lead to ACL (Access Control List) errors, turning private storage into public with one wrong click.

See also: Sweden: Svenska kraftnät suffered a data breach

For EY, a firm that oversees billions of dollars in deals and holds financially significant data, the error raises questions about oversight of high-speed infrastructure. Experts warn that attackers are constantly performing automated scans, meaning the reports are not hypothetical. The question is “how many” attackers are noticing them. As the cloud becomes more complex, continuous mapping and visibility tools are becoming essential to stay ahead of threats.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS