Back to Insights Cloud Security

Exposure of Backup Files in Public Repositories: How to Secure Your Sensitive Information

Exposure of Backup Files in Public Repositories: How to Secure Your Sensitive Information

How Unsecured Use of Cloud Resources Can Lead to Severe Exposure of Sensitive Information

In security assessments, vulnerabilities are often discovered that do not stem directly from the application itself, but rather from the improper or unsecured use of external resources. In this article, we present a case discovered during a security assessment for one of our clients’ applications, where sensitive backup (BAK) files were found stored in a public file repository intended for file downloads by application users. This exposure allowed access to sensitive information that included the application’s entire database.

Understanding the Problem: Exposure of Backup Files via Public File Repositories
How vulnerable backups can pose a serious threat to information security

Many clients utilize cloud services for storing and downloading files such as documents, software, manuals, images, and more. Users can download various files related to a specific application or system from these repositories. Occasionally, sensitive files—such as backup files—are inadvertently saved in these repositories without proper security, leading to severe exposures.

During the security assessment, we discovered downloadable PDF files containing instructions for using the application on the client’s support site. Those files were stored in a public file repository (in our case, an AWS S3 Bucket) – meaning they were accessible to any internet user. The investigation revealed that BAK files—backup files containing the entire application database, including data from the past year—were present in that same repository.

Exposure of Sensitive Information via Backup Files
How uncontrolled exposure of backups endangers organizational sensitive data

As part of the assessment, we downloaded one of the backup (BAK) files and performed an analysis. Inside the backup file, we found all the sensitive information from the client’s database, including users’ personal details, application usage logs, customer information, and more. Consequently, we were able to access all the application’s sensitive information without exploiting vulnerabilities in the application itself.

The fact that the file was available for download to anyone browsing the site meant that a malicious actor could have just as easily accessed this information, misused it, and performed actions such as identity theft, fraud, or business disruption to the client. This vulnerability has serious implications for the security of all the client’s systems, especially considering that the backup files also included information on internal processes and additional user details. Such a security failure places the company in a vulnerable and dangerous position, potentially damaging its reputation and customer trust.

Insights from IPV Security Cyber Experts
Steps to protect the organization from backup file exposure in public repositories

To prevent similar scenarios in the future, it is recommended that organizations take the following steps:

  1. Secure Storage of Backup Files – Ensure that backup files are not stored in public repositories or external servers without appropriate access control. Backup files must be stored only in secure locations protected by passwords and access controls.
  2. Restricting Access to Sensitive Files – Only authorized personnel should be granted access to sensitive files like backups. Proper permission management helps prevent unauthorized access.
  3. Implementation of Backup Procedures – A structured and secure procedure for creating and saving backup files must be implemented to ensure that sensitive information is stored securely while protecting data privacy. The policy should also include details on backing up sensitive files and their encryption methods.
  4. Regular Security Scans – Periodically scan public repositories and corporate auxiliary sites to identify sensitive files inadvertently exposed and perform deletions or implement appropriate protections.

Summary: Preventing Sensitive Information Exposure via Backup Files
How secure management of backup files can prevent severe damage to the organization’s sensitive data.

Uncontrolled preservation of backup files in public file repositories can lead to severe exposure of sensitive data, as seen in this case. The practice of uploading backup files to auxiliary sites in an unsecured manner endangers the security of the entire application ecosystem. Tighter controls are required over file management and the backup process to ensure such incidents do not occur in the future and to protect sensitive customer data.

Continue the Conversation

Facing a cybersecurity challenge? Let's talk about how a managed program can strengthen your resilience.

Start a conversation