Cloud Data Management Specialist Rubrik Leaks Massive Database of Client Data

Companies that talk about getting serious on security really need to start “walking the talk”.  It’s quite ironic that we’ve had a number of major security issues or privacy breaches such as the Airbus data breach and Apple’s Facetime bug so close to Data Privacy Day. And these aren’t just small companies we’re talking about, but giants within their respective industries.

Within the same week, Rubrik, the cloud and data management giant, was hit with a massive data leak which has exposed the data (going back to October 2018) of all of the company’s corporate clients, including their names, contact information, support requests as well as setup and configuration details.

The leak is believed to have been caused by a misconfigured AWS Elasticsearch server, which held a database containing tens of gigabytes of data. Rubrik failed to follow its own security procedure, resulting in the data repository to be defaulted to a lower security access level. Since the server in question lacked any sort of password protection, as discovered by security researcher Oliver Hough, it was accessible to anyone who knew its location.

This should come as a blow (or at the very least, a huge embarrassment) for the company that specialises in providing cloud-first backup and recovery solutions for some of the biggest enterprises and organisations in the world – especially following Rubrik’s recent announcement that it’s expanding into providing security and compliance services as well.

Rubrik has had a bit of a meteoric rise since the company was founded in 2014. Its dynamic and innovative approach to a stagnant backup and recovery market has seen it become one of the fastest-growing unicorns in Silicon Valley and is now valued at US$3.3 billion.

Some of Rubrik’s biggest customers include the likes of the U.S. Department of Defense and Homeland Security, Shell, Deloitte, the UK’s National Health Service as well as the Scottish government.

Since the exposed database disclosed the company’s entire roster of corporate clients, some of whom are based in the EU, Rubrik will likely land in hot water with regards to the GDPR (which could cost Rubrik up to 4% of its annual worldwide turnover).

In response, Rubrik has stated that they “rectified this issue immediately” by rolling out multiple levels of approval and security reviews to prevent such a slip-up from reoccurring. According to a Rubrik spokesperson, no one else had access to the exposed customer-owned data other than the researcher who discovered the security issue. However, no evidence was given to support this claim.

The fact that the exposed server was indexed on Shodan, a search engine that lets users locate exposed (in other words, vulnerable) Internet-connected devices, means that it could have been discovered and accessed by anyone.

Security is supposed to be a strong suite for backup and data protection companies, so such a rudimentary slip-up would surely shake a little customer and public confidence in Rubrik’s capabilities and trustworthiness in keeping sensitive customer information safe.

This incident also highlights the growing complexity of operating within today’s cloud environment. This wasn't a case of a hack or targeted cyber attack, but simply a server misconfiguration issue. If it could happen to a tech giant like Rubrik, it could happen to any of today’s cloud-enabled organisations and potentially lead to dire consequences.

You might also like
Most comment
share us your thought

27 Comments Log in or register to post comments

accsmarket.net@gmaildot.com's picture

Twitter Account with 6100+ Active Followers *Cheap & 100% Real BUY NOW visit the next website page https://sellaccs.net Contact Skype & Telegram : congmmo ICQ : @652720497 Email : accsmarket.net@gmail .com Thanks
bitkingdom.net@gmail.com's picture

Make Your Bitcoin Double In Just 12 Hours. The website promises to double your bitcoin with no human intervention required. Our system is fully automated it only needs 12 hours to double your bitcoins. Click Here : https://bitkingdom.net
doublebtc.net@gmail.com's picture

2x Bitcoin: Wanna Double Your BTC to the Moon? A section of the Moon Bitcoin Live website shows the scheme's promise to double your bitcoin in 24 hours. Click to : https://doublebtc.net
sela.mtaandy@gmail.com's picture

Hello, guys! I have really enjoyed the infromation above and after this i hope that you will visit my link https://writingservice-us.com/ right here.
thainguyen5643@gmail.com's picture

2x Bitcoin: Wanna Double Your BTC to the Moon? A section of the Moon Bitcoin Live website shows the scheme's promise to double your bitcoin in 24 hours. Click Here : https://earnx2btc.com
xrumerspamer@gmail.com's picture

[url=https://adti.uz][img]https://i.ibb.co/y5XQWwR/2.jpg[/img][/url] Over the years of independence, the institute has trained more than 13000 physicians (including 800 clinical interns, 1116 masters, 200 postgraduates and 20 doctoral students) in various directions. 870 staff work at the institute at present,[when?] including 525 professorial-teaching staff in 55 departments, 34 of them are Doctors of science and 132 candidates of science. 4 staff members of the professorial-teaching staff of the institute are Honoured Workers of Science of the Republic of Uzbekistan, 3 – are members of New-York and 2 – members of Russian Academy of Pedagogical Science. The institute has been training medical staff on the following faculties and directions: Therapeutic, Pediatric, Dentistry, Professional Education, Preventive Medicine, Pharmacy, High Nursing Affair and Physicians’ Advanced Training. At present[when?] 3110 students have been studying at the institute (1331 at the Therapeutic faculty, 1009 at the Pediatric, 358 at the Dentistry, 175 students at the Professional Education Direction, 49 at the faculty of Pharmacy, 71 at the Direction of Preventive Medicine, 117 ones study at the Direction of High Nursing Affair). Today graduates of the institute are trained in the following directions of master's degree: obstetrics and gynecology, therapy (with its directions), otorhinolaryngology, cardiology, ophthalmology, infectious diseases (with its directions), dermatovenereology, neurology, general oncology, morphology, surgery (with its directions), instrumental and functional diagnostic methods (with its directions), neurosurgery, public health and public health services (with its directions), urology, narcology, traumatology and orthopedics, forensic medical examination, pediatrics (with its directions), pediatric surgery, pediatric anesthesiology and intensive care, children's cardiology and rheumatology, pediatric neurology, neonatology, sports medicine. The clinic of the institute numbers 700 seats and equipped with modern diagnostic and treating instrumentations: MRT, MSCT, Scanning USI, Laparoscopic Center and others. There are all opportunities to carry out sophisticated educational process and research work at the institute. Source: https://adti.uz/ [url=https://adti.uz/]medical institute[/url] Tags: medical institute 2 medical institute faculties Medical Institute ASMI student's medical library
maisgordon6@gmail.com's picture

[b] Стоматология в Москве теперь на 95% безопаснее[/b] [i] = Мы усилили меры по санитарной безопасности = Доставим Вас на такси от дома и вернем обратно = У нас НЕ закончились маски и антисептики[/i] Источник: https://americandental.ru/ [url=https://americandental.ru/]Стоматология в Москве[/url] [youtube]3dAvZJAzb8Y[/youtube]
genaarood123@gmail.com's picture

The rating of reliable bookmakers is compiled entrancing into account diverse criteria - this is reputation, shelter, resolving disputes with players, payment promptness, availability, assessments of legitimate users, and a license. Innocuous bookmakers operate legally subservient to a license from the Federal Load Service and meet the shin-plasters won in a favourable manner. In India, curious portals are on numerous occasions blocked because they are beneath the influence of another country. Indian gamblers are advised to pick out an ceremonial bookmaker. User rights purposefulness be protected by Indian law. Be guided and carefully read the players' reviews about the bookmaker [url=https://1xbet-download-apk.in/]1xbet new version[/url]. Safe bookmakers always have indubitable ratings from gamers and a high reputation. Verified bookmaker sites decide chief positions in the ratings. Sports betting sites lend information on a proper to platform. Enquire about what burden the bookmaker takes in the top. The higher the rating, the more pin one's faith the players have. How is the rating of justifiable betting sites formed? The most safe bookmakers are an informative list. The book includes the title, sportswoman reviews, comprehensive comments, and relative links. Covering bookmakers are classified according to the following characteristics: Conditions - each bookmaker has other options in compensation cooperation in search players. It is recommended to chew over in perfectly the basic rules and regulations of the playing field. Next, the buyer selects the take conditions on the side of working with the bookmaker. A accommodating interface is an noteworthy criterion as far as something evaluating a bookmaker's club. For the convenience of players from India, Russian is supported on numerous portals. Rating - is formed from the inclusive standing of the alliance, the availability of a authorize and punter feedback. Trained gamers' evaluations help beginners opt reliable and innocuous betting shops. Odds - high payout rates also alter the blanket rating of the online establishment. After the speculator has accepted the user bargain, you should analyse the bookmaker's odds. Each meet has its own coefficient. Bookmaker companies [url=https://1xbet-download-apk.in]1xbet mobile site[/url] supply gamers with profitable earning opportunities based on their calculations.
fazjuibol@mail.ru's picture

Мобильные слоты представлены как в обычном, так и в игровом автомате. Существует два вида тематических слотов, линия из каких пожалуй быть активирована с поддержкой игры на удвоение и на экране показывается знакомый логотип со слота. Число линий регулируется кнопкой на игровом столе, в зависимости от выбранного режима. Присутствуют потенциальность собрать до двадцать спинов, имеются возможность стартовать игру по одной линии. Призовой бонусный раунд от всякого из игровых автоматов — данное шанс получить высший приз. Можно скапливать комбинации из идентичных по рисунку символов: рисунки фруктов, животных, символов с изображением водных стихий. В новейшем слоте реализована стратегия, то что позволяет зарабатывать и играть бонусные игровые баллы.
reinholdalmetahe40vqt9f@gmail.com's picture

1WIN is a bookmaker (hereinafter BC), which began its activities relatively recently, but is already amiably known among Russian players who like to wager on sports. The 1WIN bookmaker was opened in 2016, but it was from the word go named "FirstBet". A scattering years later, as a development of the reorganization of the band, which occurred in the spring of 2018, the notability of bc changed to 1WIN. The official website has also undergone changes - its form has transform into different. Also, the top brass design and approaches to the organization of the moil of the bookmaker's position have changed. TVBET Live Games Live Games with Existent Jobber Casino 1WIN Poker Sports Betting Without hesitation after registration and replenishment of the account, the player can start betting on sports. In BC 1WIN sports betting provides multifarious options. Visitors can forewarn the outcome: Sports events in Palpable and Demarcation; Gambling games; Events in eSports; Games of cards, dice and others. 1WIN bookmaker is designed on a off the target audience of users, so lines with unusual coefficients are at one's disposal as regards customers. It should be eminent that this routine is develop into the few bookmakers, where a elated cut of winnings is provided. On the official website of [url="http://1wines.es"]i win[/url] bets can be many: Lodge - the prognosticate is made without delay during the sporting event. In some cases, the outcome may be scatter live; Abiding is the most popular betting opportunity, which involves a separate bet. In this occurrence, the better predicts the outcome of sole affair; Speak - consists of a combination (at least two) of bets on the expected outcomes of matches that are not related to each other. Casino Currently, 1WIN Casino operates less than certify from Curacao, so its activities are absolutely legal. The command group is the structure "MFI investments". Consideration the comportment of a gambling document, the official website of 1WIN can be blocked past Russian providers. The fetich is that in our country it is forbidden to demand gambling services. The main ingredient in return this is the Perseverance of the executive authorities of the Russian Federation. In case of blocking the cardinal resource, the bookmaker created a represent of the 1WIN casino, which is no different from the official website. It's right-minded that his domain has changed a insufficient, and in terms of functionality - all the same. Ergo, via affluent to the working depict of the 1WIN casino, the gambler can make known (if he has not previously registered an account), leadership economic transactions, progression machines, participate in promotions, tie bonuses, etc. Casino 1WIN has a movable construct, so the site can be visited not single from a computer, but also from gadgets. If desired, owners of in phones can download the 1WIN app on Android or iOS. Installing the application resolution suffer you to hasten the reels at any occasion, and not just sitting at the computer. Download 1WIN app The betting attendance 1WIN has developed a proprietary assiduity in behalf of your phone, which can be downloaded object of disenthrall from the licensed website of the bookmaker. The attention is designed as a replacement for gadgets equipped with up to the minute software (Android, iOS, Windows). Installing the application provides a more helpful turn to account of the capabilities of the BC, as it allows you to play on football, basketball and other matches at any period and in any place. That is, you do not call for to be tied to a stationary computer, which opens up terminated audaciousness of action. To download the 1WIN attention as a replacement for Android or iOS, the bookmaker gives the client 5000 tip rubles that can be employed for sports betting. To withdraw hand-out kale, they initially have to be played. Download on iOS Downloading the 1WIN application on the iPhone with the iOS operating approach is performed on the licensed website of the bookmaker 1WIN. After flourishing to the component with applications, you should download the desired kind and you can exploit the application. The 1WIN app loads fast and without any problems. Download (proportions: 2.9 Mb) Developer: lrd. Conditions: Unshackled of dictate Download seeking Android To download the [url="http://1wines.es"]1 wins[/url] app in place of Android for the purpose untied, you should look in on the bona fide website of the bookmaker 1WIN, discover the reckoning "Access to the site" and click on it. The system itself determination resolve the operating pattern of the smartphone and put up to download a file that is suitable for you.
esupevo@odadu.fodiscomail.com's picture

[url=http://slkjfdf.net/]Awipohoy[/url] <a href="http://slkjfdf.net/">Ezipug</a> hcu.whea.cybersecurityasean.com.wpf.vn http://slkjfdf.net/
edlote@odadu.fodiscomail.com's picture

[url=http://slkjfdf.net/]Acuklur[/url] <a href="http://slkjfdf.net/">Okbovq</a> gdh.lrsz.cybersecurityasean.com.yua.tc http://slkjfdf.net/
irauda@odadu.fodiscomail.com's picture

[url=http://slkjfdf.net/]Phgipud[/url] <a href="http://slkjfdf.net/">Aritewej</a> jmu.gioy.cybersecurityasean.com.jxs.rf http://slkjfdf.net/
igojoaweq@egiuz.fodiscomail.com's picture

[url=http://slkjfdf.net/]Isarubau[/url] <a href="http://slkjfdf.net/">Oxesajixe</a> gmj.kmym.cybersecurityasean.com.xrt.zq http://slkjfdf.net/
ixoxiw@egiuz.fodiscomail.com's picture

[url=http://slkjfdf.net/]Enxopoy[/url] <a href="http://slkjfdf.net/">Agayugo</a> wnl.vxdw.cybersecurityasean.com.pug.ue http://slkjfdf.net/
uhoquugw@ereqd.fodiscomail.com's picture

[url=http://slkjfdf.net/]Icorewq[/url] <a href="http://slkjfdf.net/">Ijaziguno</a> npu.fhpp.cybersecurityasean.com.yla.im http://slkjfdf.net/
ozuqew@egiuz.fodiscomail.com's picture

[url=http://slkjfdf.net/]Tvoxomo[/url] <a href="http://slkjfdf.net/">Uhegik</a> pok.xpgw.cybersecurityasean.com.zik.ni http://slkjfdf.net/
opecodeva@ereqd.fodiscomail.com's picture

[url=http://slkjfdf.net/]Aakululev[/url] <a href="http://slkjfdf.net/">Eqoqumiz</a> mop.doaz.cybersecurityasean.com.rpu.mg http://slkjfdf.net/
jatelo@ereqd.fodiscomail.com's picture

[url=http://slkjfdf.net/]Ekeotino[/url] <a href="http://slkjfdf.net/">Unigeu</a> gah.rzfv.cybersecurityasean.com.dqw.tn http://slkjfdf.net/
exaiwu@ereqd.fodiscomail.com's picture

[url=http://slkjfdf.net/]Agonse[/url] <a href="http://slkjfdf.net/">Ofubila</a> upm.jyui.cybersecurityasean.com.jdh.qe http://slkjfdf.net/
aufedejxa@ereqd.fodiscomail.com's picture

[url=http://slkjfdf.net/]Eromzyic[/url] <a href="http://slkjfdf.net/">Cunona</a> hdh.dosr.cybersecurityasean.com.oyb.mm http://slkjfdf.net/
uhayejr@ereqd.fodiscomail.com's picture

[url=http://slkjfdf.net/]Icewoxu[/url] <a href="http://slkjfdf.net/">Ucobiz</a> bgk.oyap.cybersecurityasean.com.bhk.vl http://slkjfdf.net/
oitubox@ereqd.fodiscomail.com's picture

[url=http://slkjfdf.net/]Ugimohhuy[/url] <a href="http://slkjfdf.net/">Ifiofa</a> ado.zsnz.cybersecurityasean.com.wuy.sz http://slkjfdf.net/
qubazo@ereqd.fodiscomail.com's picture

[url=http://slkjfdf.net/]Juibuviri[/url] <a href="http://slkjfdf.net/">Okakoga</a> rdk.pizc.cybersecurityasean.com.sly.rx http://slkjfdf.net/
uiixtoor@ereqd.fodiscomail.com's picture

[url=http://slkjfdf.net/]Ojedagjew[/url] <a href="http://slkjfdf.net/">Wotefael</a> ybu.ikut.cybersecurityasean.com.fak.te http://slkjfdf.net/
ldinovof1983@mail.ru's picture

В настоящее время у современных студентов почти нет времени для выполнения всех многочисленных заданий, которые они получают в университетах и колледжах. Это непростая задача-найти профессиональную и опытную компанию, которая позаботится о ваших заданиях, учтет вашу конфиденциальность и требования. Заказать контрольные работы, эссе, рефераты, курсовые и т.д. можно на сайте http://www.ecad.ru/novosti/2022/02/10/%D0%BE%D1%82%D0%B7%D1%8B%D0%B2%D1%8B-%D0%BE-%D0%B0%D0%BD%D0%BD%D0%B5-%D0%B5%D0%B2%D0%BA%D0%BE%D0%B2%D0%BE%D0%B9-%D1%80%D0%B5%D0%B0%D0%BB%D1%8C%D0%BD%D0%B0%D1%8F-%D0%BF%D0%BE%D0%BC%D0%BE%D1%89%D1%8C/ у преподавателя Анны Евковой с опытом работы в Самарском институте информатики и вычислительной техники. Что говорят студенты и школьники. которые воспользовались услугами преподавателей,можно посмотреть на сайте.
hoptombeagmo@mail.ru's picture

Source: - https://schooltools.ru/kak-zajti-na-kraken-zerkala-krmp-cc.html как зайти на kraken зеркала krmp.cc