EY allegedly leaked a massive 4TB database online, exposing the company’s secrets online for all to see.


  • EY exposed 4TB SQL backup containing sensitive credentials and application secrets online
  • Neo Security notified EY; researchers suspect threat actors may have already accessed the data
  • EY responded professionally but took a week to fully resolve the issue.

Ernst & Young (EY), one of the world’s largest accounting firms, kept a complete backup of its database on the public Internet, accessible to anyone who knew where to look. The backup, a .BAK file, was 4TB in size and contained sensitive information such as schema, data, stored procedures, and “all secrets stored in these tables.”

So said a security researcher at Neo Security, who was doing “low-level tooling work” when a SQL Server BAK file caught his eye.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top