Test environment let anyone access live customer data
A company’s externally accessible staging server was connected to a database containing live customer information, creating an opportunity for unauthorised access. The environment had been created temporarily to demonstrate an application and test a cloud migration, but remained active for months without production-level authentication or access controls.
The vulnerability was discovered during a security audit before the company moved local systems to the cloud. The database file was plainly named `master_test_final.sql`, and the staging environment had reportedly been running for six months; access was restricted immediately, followed by a review of other development and test systems. The incident highlights how forgotten temporary infrastructure can pose serious risks when it handles real data.
- Exposed staging server connected to live customer data.
- Temporary environment remained active for six months.
- Company restricted access and reviewed other test systems.