Monday, April 28, 2025
HomeSecurity News1.5 Billion Files Exposed on Internet from Misconfigured FTP, SMB & S3...

1.5 Billion Files Exposed on Internet from Misconfigured FTP, SMB & S3 Buckets:12 Petabytes Publicly Available Sensitive data

Published on

SIEM as a Service

Follow Us on Google News

More than 1.5 billion sensitive files exposed online publicly that including Patent Application, Payroll, Tax Return, Patient List, Copyright Application and Source Code.

The data exposed is not by means of any cybercriminal activities, it has been publicly available with the misconfigured cloud storage, file exchange protocols, and file sharing services

According to digital shadows report more than 1.5 billion sensitive files publically exposed across the three-month period. The exposed data is of 12,000 terabytes that available publicly on open Amazon S3 buckets, Rsync, SMB, FTP servers, misconfigured websites, and Network Attached Storage (NAS) drives.

- Advertisement - Google News
1.5 billion sensitive files

With the data exposed Amazon S3 buckets accounts 7(percent), whereas other file sharing service like SMB (33 percent), rsync (28 percent) and FTP (26 percent) account larger portion of the exposure than the Amazon S3 buckets.

Also Read: Massive Cyber Attack Across the World Against ISP’s & Data Centres: More than 200,000 Cisco Switches Hacked

“The United States has the highest number of publicly-visible files shared across SMB, FTP, Web Index and NAS devices of any single country. With the 1.5 billion of sensitive files, 537 Million files are geolocated in the European Union,” said Digital Shadows.

1.5 billion sensitive files

“Digital Shadows analysis of these files indicates that organizations and individuals are unwittingly exposing vast volumes of data that aid attackers with a variety of motives, including espionage actors and financially-motivated actors criminals,”

Publicly exposed data contains a large amount of the employee data such as Payroll files (707,960) and Tax Return files (64,048). More than 2 Million of files that contain personal health information like MRIs based in Italy exposed.

The exposed data includes the Source Code, Patient List accounted about 95,434 and 4,548 respectively. Exposed data is a goldmine for attackers they can use the publicly available data to launch cyber attacks. the exposed information cut’s off their reconnaissance.

Shockingly some highly sensitive information’s such as security audit reports, network infrastructure details and penetration testing reports are stored online publicly.

Your data is a big part of your company. There are a hundred ways that to right away lose all of them which might get you out of business. There is a growing need to educate organizations and nd other people concerning the importance of securing sensitive data.

We heard about a number of Amazon bucket data exposures but the sensitive data exposed from other file exchange protocols and sharing services is greater than the S3 buckets.

GDPR comes into action on 25 May 2018 and it contains clear regulation on the protection of personal data and if the data is misgoverned companies should pay huge fines and damage in reputation.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Windows 11 25H2 Expected to Launch with Minor Changes

Microsoft is quietly preparing the next update to its flagship operating system, Windows 11 25H2,...

China Claims U.S. Cyberattack Targeted Leading Encryption Company

China has accused U.S. intelligence agencies of carrying out a sophisticated cyberattack against one...

Critical FastCGI Library Flaw Exposes Embedded Devices to Code Execution

A severe vulnerability (CVE-2025-23016) in the FastCGI library-a core component of lightweight web server...

Viasat Modems Zero-Day Vulnerabilities Let Attackers Execute Remote Code

A severe zero-day vulnerability has been uncovered in multiple Viasat satellite modem models, including...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

FBI Alerts Public to Scammers Posing as IC3 Officials in Fraud Scheme

The Federal Bureau of Investigation (FBI) has issued a warning regarding an emerging scam...

New ‘Waiting Thread Hijacking’ Malware Technique Evades Modern Security Measures

Security researchers have unveiled a new malware process injection technique dubbed "Waiting Thread Hijacking"...

EU’s GDPR Article 7 Poses New Challenges for Businesses To Secure AI-Generated Image Data

As businesses worldwide embrace digital transformation, the European Union’s General Data Protection Regulation (GDPR),...