Get notified of our articles as they're available
Your data is safe - no sharing, no spam.
UpGuard identified a publicly accessible AWS S3 repository operated by NICE Systems, a Verizon third-party vendor, that exposed customer call-centre logs containing names, addresses, phone numbers, account details and some unmasked Verizon account PINs.
data loss aws s3
UpGuard reported that Deep Root Analytics exposed 1.1 TB of downloadable data for up to 198 million potential U.S. voters through an Amazon Web Services S3 bucket with no access protections.
aws s3 data loss
This incident is a classic misconfiguration leading to total data breach - Elasticsearch deployed on EC2 without authentication on port 9200 and left reachable from the public internet. This is not just a service hardening issue; it is an architectural failure in network placement, exposure control and access design.
aws ec2 data loss
Imperva disclosed that its Cloud WAF data exposure stemmed from unauthorised use of an administrative API key in a production AWS account, leading to access to a database snapshot containing email addresses, hashed and salted passwords, API keys and TLS keys for a subset of customers.
ec2 aws rds iam
Microsoft disclosed that an internal customer support case analytics database was exposed after a network security group change on December 5, 2019 introduced overly permissive security rules and the issue was not remediated until December 31, 2019.
azure data loss
In a typical incident where S3 buckets have been left exposed to the internet, UpGuard reported that Accenture left four AWS S3 buckets publicly accessible on the internet, allowing anyone with the bucket URLs to download sensitive data tied to the Accenture Cloud Platform and related environments.
s3 aws data loss
Code Spaces shut down after an unauthorised party accessed its AWS account and permanently deleted most customer data, including Apache Subversion repositories, Elastic Block Store volumes and all virtual machines, leaving the company unable to restore service.
data loss s3 aws
Dow Jones exposed customer and Risk & Compliance data after an Amazon S3 bucket was misconfigured to permit access to AWS “authenticated users,” which UpGuard identified as effectively open to anyone with a free AWS account.
aws s3 data loss
Due to the diminished activity in Private Equity over the last couple of years, PricewaterhouseCoopers has highlighted a shift from calendar-driven IPO planning to readiness-driven execution, with successful 2025 issuers investing 18 to 24 months in advance in governance, reporting infrastructure and institutional preparation.
due diligence risk assessment exit strategy
BleepingComputer reports that Stryker needed roughly three weeks to return to a broadly similar level of operation after attackers allegedly stole 50TB of data and wiped nearly 80,000 devices. Even then, recovery was not complete: production was still moving toward peak capacity rather than fully restored.
penetration testing cloud automation