EY reportedly leaked massive 4TB database online – exposing company secrets online for all to see


  • EY disclosed a 4TB SQL backup online containing sensitive credentials and application secrets
  • Neo Security warned EY; researchers suspect that threat actors have already gained access to the data
  • EY responded professionally, but it took a week to fix the problem

Ernst & Young (EY), one of the world’s largest accounting firms, kept a complete database backup on the public Internet, available to anyone who knew where to look. The backup, a .BAK file, was 4 TB in size and contained sensitive information such as schema, data, stored procedures and “every secret stored in these tables”.

This is according to a security researcher at Neo Security who was doing “low-level tool work” when a SQL Server BAK file caught his eye.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top