4TB Database Backup Exposed Online | Security Risk

by priyanka.patel tech editor

Ernst & Young Hit by Massive data Leak: 4TB of Sensitive Data Exposed Online

A staggering 4 terabytes of sensitive data belonging to professional services giant Ernst & Young (EY) was discovered exposed on the internet, highlighting the persistent risks of cloud security and the critical need for robust vulnerability reporting programs. The unencrypted database backup, containing critical credentials and authentication tokens, was accessible for a period of time before being secured, raising serious questions about data protection practices at one of the world’s “Big Four” accounting firms.

Did you know? – A terabyte is equivalent to approximately 1,000 gigabytes. Four terabytes could hold roughly 1 million high-resolution photos or 500 hours of HD video.

The Discovery and Scope of the Breach

On October 29, 2025, Dutch security firm Neo Security publicly disclosed the data leak after identifying a readily accessible SQL database backup file hosted on Microsoft Azure. neo Security routinely scans the internet, creating a “map of the Internet and its contents,” and frequently encounters briefly exposed database files. However, the sheer size – over 4 terabytes – and the nature of the data within this particular file immediately raised alarm bells.

According to reports from The Register, the exposed backup contained a treasure trove of data for potential attackers, including API keys, cached authentication tokens, session tokens, service account passwords, and user credentials. “Everything is stored unencrypted and unprotected in a database backup,” one security analyst stated, describing the situation as a “jack pot” for malicious actors.

EY’s Identity Confirmed and the Race to Secure the Data

After meticulous investigation, including examining readable data records within the backup, Neo Security researchers confirmed the database belonged to Ernst & Young. Recognizing the urgency, the team immediately attempted to contact EY’s security personnel to have the file taken offline. This proved unexpectedly challenging.

The firm lacked a dedicated security@ email address and, crucially, a formal vulnerability reporting program. Compounding the issue, the discovery occurred on a weekend. After 15 unsuccessful attempts, a Neo Security researcher finally connected with an EY employee via LinkedIn who facilitated contact with the firm’s computer Security Incident Response Team (CSIRT).

Pro tip: – Organizations shoudl establish a clear and easily accessible vulnerability disclosure program, including a dedicated email address, to facilitate responsible reporting from security researchers.

Swift Response and a Rare Example of Collaboration

The EY CSIRT team responded swiftly and professionally, resolving the issue within a week, according to Neo Security. This rapid response stands in stark contrast to experiences reported by other security researchers, who have faced threats of legal action, ignored reports, or even dismissive responses like “This isn’t a bug, it’s a feature.”

“This professional reaction is rare,” a company release noted, underscoring the importance of collaborative security practices. The incident serves as a potent reminder of the inherent risks associated with cloud infrastructure and the public internet, where even brief exposures can have devastating consequences.

Reader question: – How can companies balance the need for rapid innovation with the imperative of robust security measures in cloud environments?

About Ernst & Young

ernst & Young Global limited (EY Global) generated $40.2 billion in revenue during the 2020/21 financial year,solidifying its position as one of the “Big Four” accounting firms.


Expanded News Report:

Why did this happen? The data leak occurred due to an unencrypted database backup being inadvertently exposed on Microsoft Azure. The root cause appears to be insufficient security configurations and a lack of a formal vulnerability reporting program at EY. The unencrypted nature of the data substantially exacerbated the risk.

Who was involved? Ernst & Young (EY) was the victim of the data breach. Neo Security, a

Leave a Comment