Sign and logo of EY on EY Tower in downtown Toronto
– Getty Images

A trove of some four terabytes (TB) of confidential data from consulting giant EY was found completely exposed to the public internet.

The leak, uncovered by researchers from Neo Security and first reported by The Register, was from an SQL backup file that contained everything from service account passwords and user credentials to cached authentication tokens and API keys.

To put the leak into perspective, the researcher who unearthed the EY exposure previously found an entire ransomware incident that was 8 kilobytes – about the size of some small text files. EY’s apparent backup breach was 4TB, the equivalent of between 500 to 1,000 full HD movies.

Neo Security staff likened the leak to “finding the master blueprint and the physical keys to a vault, just sitting there with a note that says ‘free to a good home.’”

“That file was sitting there, publicly accessible, for an unknown amount of time. [It] could have been hours, could have been days,” a Neo Security blog post reads. “In that window, with the scanning infrastructure that exists, it's not a question of if someone found it. It's a question of how many.”

How did 4TB of EY data get leaked?

According to Neo Security, the origin of the mammoth data breach likely stemmed from a botched migration to the cloud.

Bringing data from an on-premise database to the cloud for a one-time migration sees a source database essentially copied and then transferred to the destination instance.

However, in the instance of this 4TB trove, the engineer tasked with the migration inadvertently set the backup file to public – not private – which led to it being leaked online.

“Modern cloud platforms make it trivially easy to export and back up your database. A few clicks, select your database, choose a destination bucket, and you're done. The export happens automatically in the background,” Neo Security’s blog post reads.

“But here's where it gets dangerous: one wrong click, one typo in a bucket name, and suddenly your private data is sitting in a public bucket. You meant to export to company-internal-backups but accidentally typed company-public-assets. Or you created a new bucket for the export, forgot to set it to private, and the cloud provider defaults to public.”

Once uncovered, the Neo Security team tried to contact EY, but due to it being the weekend, they were forced to turn to LinkedIn to get hold of someone, and were only put through to the relevant security staff “after 15 attempts.”

One week later, the leak was triaged and fully remediated, though the damage had already been done.

“Here's what concerns our researcher,” Neo Security wrote. “If EY, with all their resources, security teams, compliance frameworks, ISO certifications, and Big Four budget, can have a 4TB SQL Server backup sitting publicly accessible on the internet, then anyone can.”

In a statement sent to SDxCentral, an EY spokesperson said: "Several months ago, EY became aware of a potential data exposure and immediately remediated the issue. No client information, personal data, or confidential EY data has been impacted. The issue was localized to an entity that was acquired by EY Italy and was unconnected to EY global cloud and technology systems."