Skip to main content

Data management giant Rubrik leaked a massive database of client data in security lapse

A server security lapse has exposed a massive database of customer information belonging to Rubrik, an IT security and cloud data management giant.

The company pulled the server offline Tuesday within an hour of TechCrunch alerting the company, after the data was found by security researcher Oliver Hough. The exposed server wasn’t protected with a password, allowing access to anyone who knew where to find the server.

The database itself, running on a hosted Amazon Elasticsearch server, was storing tens of gigabytes of data, including customer names, contact information, and case work for each corporate customer.

It’s believed the data goes back to October 2018, according to timestamps found inside.

A portion of the database was dedicated to all of the company’s corporate clients, allowing its customers to interact with Rubrik staff with issues or complaints. This included the contents emails that had been ingested into the system from customers — including, in many cases, their email signature with names, job titles and phone numbers. From a cursory review, we also found some emails included sensitive information about that customers’ setup and configuration.

Each company record also includes descriptive profile information, such as if it’s a Global 2000 or a Fortune 500 ranked company to determine the importance of the account, as well as the go-to person’s name and phone number.

It’s somewhat ironic, given that the IT unicorn, valued at $3.3 billion, recently announced that it’s expanding into security and compliance services.

Ribrik has thousands of major clients, and publicizes big names such as the Scottish Government, the U.S. Department of Defense, and CarePoint Health, among others, on its website.

But the client database disclosed what appears to be the company’s entire roster of corporate customers, including Deloitte, Shell, Amalgamated Bank, the U.K. National Health Service, and Homeland Security and other federal government departments.

In remarks, Rubrik said it was investigating.

“While building a new solution for customer support, a sandbox environment containing a subset of our customer corporate contact information and support interaction data was potentially accessible for a brief period of time,” said a spokesperson for Rubrik. “We rectified this issue immediately.”

“We also confirmed that no customer-owned data was exposed,” the spokesperson added. The company also said that, “other than the security researcher who discovered this issue, no one has accessed this environment,” without providing evidence for that claim.

It’s not known who might have accessed it, but the exposed server was indexed on Shodan, a search engine for exposed devices and databases, making it easily discoverable and accessible.

“We have traced the cause to human error, a default access setting was not changed per our standard practice. We have enacted changes to our processes to prevent this from happening again. Privacy and security is our top concern and we sincerely apologize for the mistake,” the spokesperson said.

Rubrik didn’t say if it would notify its customers or state regulators, per data breach notification laws.

Given that European businesses are included in the exposed data, Rubrik could face financial penalties of up to four percent of its global annual revenue if found to be in breach of the EU’s recently implemented GDPR data protection rules.

Rubrik’s data exposure came just months after data management and backup rival Veeam exposed millions of email addresses in its own data exposure.



from TechCrunch https://tcrn.ch/2DHOVPi
via IFTTT

Comments

Popular posts from this blog

The Silent Revolution of On-Device AI: Why the Cloud Is No Longer King

Introduction For years, artificial intelligence has meant one thing: the cloud. Whether you’re asking ChatGPT a question, editing a photo with AI tools, or getting recommendations on Netflix — those decisions happen on distant servers, not your device. But that’s changing. Thanks to major advances in silicon, model compression, and memory architecture, AI is quietly migrating from giant data centres to the palm of your hand. Your phone, your laptop, your smartwatch — all are becoming AI engines in their own right. It’s a shift that redefines not just how AI works, but who controls it, how private it is, and what it can do for you. This article explores the rise of on-device AI — how it works, why it matters, and why the cloud’s days as the centre of the AI universe might be numbered. What Is On-Device AI? On-device AI refers to machine learning models that run locally on your smartphone, tablet, laptop, or edge device — without needing constant access to the cloud. In practi...

Apple’s AI Push: Everything We Know About Apple Intelligence So Far

Apple’s WWDC 2025 confirmed what many suspected: Apple is finally making a serious leap into artificial intelligence. Dubbed “Apple Intelligence,” the suite of AI-powered tools, enhancements, and integrations marks the company’s biggest software evolution in a decade. But unlike competitors racing to plug AI into everything, Apple is taking a slower, more deliberate approach — one rooted in privacy, on-device processing, and ecosystem synergy. If you’re wondering what Apple Intelligence actually is, how it works, and what it means for your iPhone, iPad, or Mac, you’re in the right place. This article breaks it all down.   What Is Apple Intelligence? Let’s get the terminology clear first. Apple Intelligence isn’t a product — it’s a platform. It’s not just a chatbot. It’s a system-wide integration of generative AI, machine learning, and personal context awareness, embedded across Apple’s OS platforms. Think of it as a foundational AI layer stitched into iOS 18, iPadOS 18, and m...

Max Q: Anomalous

Hello and welcome back to Max Q! Last week wasn’t the most successful for spaceflight missions. We’ll get into that a bit more below. In this issue: First up, a botched launch from Virgin Orbit… …followed by one from ABL Space Systems News from Rocket Lab, World View and more Virgin Orbit’s botched launch highlights shaky financial future After Virgin Orbit’s launch failure last Monday, during which the mission experienced an  “anomaly” that prevented the rocket from reaching orbit, I went back over the company’s financials — and things aren’t looking good. For Virgin Orbit, this year has likely been completely turned on its head. The company was aiming for three launches this year, but everything will remain grounded until the cause of the anomaly has been identified and resolved. It’s unclear how long that will take, but likely at least three months. Add this delay to Virgin’s dwindling cash reserves and you have a foundation that’s suddenly much shakier than before. ...