Researchers find Box enterprise cloud storage accounts leaking sensitive data like prices for donated body parts and backdoor passwords to city waterworks
Context & Ripple Effects
This finding lands in a long run of researcher-discovered exposures on enterprise infrastructure: Accenture left unencrypted passwords on exposed servers in 2017, a consultant for Democratic campaigns ran an open NAS full of fundraiser contacts in 2018, and just weeks before this story Rubrik — a company that sells data management — left a server online without a password.
The pattern matters because the vendor named in each headline is rarely the party at fault: Box provides the storage, but its enterprise customers configured the sharing. The same dynamic resurfaced months later when researchers found hundreds of exposed AWS EBS snapshots leaking VPN configs and government data.
First-order effects
- The account owners are exposed right now — an organization trading in donated body parts has its pricing public, and a city waterworks has its backdoor passwords readable, giving attackers immediate operational access.
- Box faces customer questions about whether its default sharing and permission settings make these leaks too easy, even though the misconfiguration sits on the customer side.
Second-order effects
- Cloud collaboration rivals must answer the same default-settings question, pushing the market toward admin-level auditing, external-sharing controls, and data-loss-prevention tooling as standard enterprise features.
- Enterprise buyers gain leverage in procurement: the recurring drumbeat of exposures gives security teams concrete grounds to demand proof of configuration hygiene from every SaaS vendor they store sensitive files with.
Third-order effects
- If the pattern holds, the industry moves from user-configured sharing to secure-by-default architecture, with vendors treating open links and permissive folders as defects rather than conveniences.
- Regulators and insurers increasingly treat customer-side cloud misconfiguration as a board-level risk, since the shared-responsibility model leaves the most damaging failures outside the vendor's control.
The trend: Enterprise cloud platforms are being pushed from user-configured sharing toward secure-by-default design as researchers keep surfacing the same class of customer-side misconfiguration across Box, AWS, and beyond.