Test environment let anyone access live customer data

← Back to the feed

Test environment let anyone access live customer data

The Register · 2 weeks ago

A company’s externally accessible staging server was connected to a database containing live customer information, creating an opportunity for unauthorised access. The environment had been created temporarily to demonstrate an application and test a cloud migration, but remained active for months without production-level authentication or access controls.

The vulnerability was discovered during a security audit before the company moved local systems to the cloud. The database file was plainly named `master_test_final.sql`, and the staging environment had reportedly been running for six months; access was restricted immediately, followed by a review of other development and test systems. The incident highlights how forgotten temporary infrastructure can pose serious risks when it handles real data.

  • Exposed staging server connected to live customer data.
  • Temporary environment remained active for six months.
  • Company restricted access and reviewed other test systems.

Business Environment Markets Science

Read the full article at the source →