Finance company stores DB credentials in helpfully labeled spreadsheet
ID: c1c9abc5-1595-5cec-bfef-8a8a630a5f94
STIX ID: report--c1c9abc5-1595-5cec-bfef-8a8a630a5f94
Feed Name: The Register (Security)
Threat Score
An audit of a fintech startup discovered an Excel file named 'Prod_DB_Root_Creds_DO_NOT_SHARE.xlsx' in a company-wide SharePoint folder accessible to all employees and contractors; the file contained production DB root credentials and master AWS IAM keys, was protected by a guessable password (company+year), and had existed for eight months—presenting a high-risk exposure of sensitive credentials though no active exploitation was reported.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
