back to article Back up a minute: Veeam database config snafu exposed millions of customer records

A misconfigured server at data recovery and backup firm Veeam exposed millions of email addresses. Close up of tangled tape Reel talk: You know what's safely offline? Tape. Data protection outfit Veeam inks deal with Quantum READ MORE Security researcher Bob Diachenko discovered the 200GB cache of email addresses, names and …

      Re: oooops. -- "prospect"

      "...non-sensitive records (i.e. prospect email addresses)"

      Like your competitors would never want to snoop your prospects and you would be happy to share...

      ...and you prospects would somehow want to be on spam lists?

      Come on; this might not be the most sensitive stuff; but relatively speaking, most data exists because it has some value--and therefore, some sensitivity.

      Proper risk assessment means identifying your data assets and determining their value if lost or compromised. And, if you think that's "non-sensitive", then you probably haven't identified and assessed any of your data assets--which is sadly typical of many businesses.

    Until the next flaw is found

    We have now ensured that ALL Veeam databases are secure.

    "ALL" is a pretty big word, considering an investigation is still taking place.

    Assuming they have EU resident data subjects in there, have they notified a European regulator? If not, this would be a case for a fine big enough to discourage others from not doing so.

    Are they..

    Backing up British Airways?

    A data company that overlooks the basics..

      Re: Are they..

      Anybody want to wager on whether the security people at British Airways suddenly lost interest in their work when they learned BA was talking to IBM about taking everything over? Particularly with IBM's reputation for massive layoffs?

        Re: Are they..

        And ruining formerly reasonable workplaces ;)

    e-mails vs. user base

    Sure I can see the discrepancy. I know there are multiple addresses registered for our office. I'm fiddling with the free version on the side, with my own login and another e-mail address. How many events did Veeam give away swag for registering for their newsletter...

    GDPR Fine

    How does the GDPR fine work when a non-EU company does not publish annual revenue?

    Off to the Cloud...

    Do they recall writing this I wonder..?

    Cloud backup security concerns.

    How about getting someone to write a script that periodically tests your cloud infrastructure for potential leaks and sends an email or text msg to someone who will notice?

    Got a mail today:

    The exposed database contained non-sensitive marketing records, such as name and email address, and in some instances IP addresses

    WTF! These data are sensitive to me, and that's all that matters, they are my data FFS.

    Marketing bastards.

