EY reportedly leaked a massive 4TB database online, exposing company secrets online for all to see.



  • EY exposed 4TB SQL backup containing sensitive credentials and application secrets online
  • Neo Security warned EY; Researchers suspect that threat actors may have already accessed the data.
  • EY responded professionally but took a week to fully resolve the issue.

Ernst & Young (EY), one of the world’s largest accounting firms, kept a complete backup of the database on the public Internet, available to anyone who knew where to look. The backup, a .BAK file, was 4 TB in size and contained sensitive information such as schemas, data, stored procedures, and “all the secrets stored in those tables.”

This is according to a security researcher at Neo Security, who was performing “low-level tooling work” when a SQL Server BAK file caught his attention.



Leave a Comment

Your email address will not be published. Required fields are marked *