Report: ~2.3B files, including sensitive info like credit card and medical data, are exposed via publicly accessible online file storage servers, up 50% YoY
Digital Shadows research finds that the number of exposed files — including sensitive information — has risen by 50 percent compared with last year.
Context & Ripple Effects
The scale here is worth measuring against the corpus's own baseline: back in 2015, researchers counted roughly 1B data records compromised worldwide in 2014 across 1,500 breaches — a figure that then represented an alarming annual total. Digital Shadows now finds ~2.3B individual files sitting openly accessible at any given moment, no breach required, including credit card and medical data.
The health-care thread running through the related coverage explains why the file mix matters: within weeks of this report came word that more than 32M patient records were stolen in just the first half of 2019, double all of 2018 — and later coverage of unsecured medical image servers and HHS counts showing 40M+ people affected in 2021 confirms exposure kept compounding.
First-order effects
- Any organization whose files are among the ~2.3B exposed — with card numbers and medical records explicitly named — faces immediate breach-level risk without having been 'hacked' at all, since the data is simply reachable.
Second-order effects
- Cloud storage vendors come under pressure to change default configurations toward private-by-default, because customer misconfiguration is now producing headline-scale exposure numbers that attach to the platform's name.
- Health-care regulators and payers get a widening evidentiary trail — this report plus the patient-record theft and medical-image findings — pushing audits and enforcement toward hospitals' storage practices specifically.
Third-order effects
- If the trajectory holds, the industry's definition of a 'breach' shifts from perimeter intrusion to continuous exposure management, making always-on external monitoring — the market Digital Shadows sells into — a standard control rather than a niche service.
The trend: Accidental public exposure of cloud-stored files is overtaking targeted hacking as the fastest-growing source of large-scale data leaks, with health data as the recurring casualty.