Misconfigured Box Accounts Can Expose Data

Robinson+Cole Data Privacy + Security Insider
Contact

Security researchers at Adversis have discovered that dozens of companies have inadvertently leaked corporate and customer data through their Box enterprise storage accounts because staff are sharing public links to their private corporate files.

According to the researchers, data stored in Box enterprise accounts is private by default, but if users share the files or folders, the data can be publicly accessible. The researchers found that when they used a script to scan for Box accounts with lists of company names and wildcard searches, they found more than 90 companies, some very well known, including Box, with publicly accessible folders.

Some of the folders contained innocuous data, but others included personal information, including passport photographs, bank account information, employee lists, Social Security numbers, and passwords.

Box responded to the discovery by stating that customers are the ones deciding the security level of their enterprise accounts, and although Box provides controls so the customers can choose the level of security they want, if users are sharing files or folders broadly, the folders may be made accessible. Box is attempting to make the security settings more clear and to educate its customers on how files and folders can be shared.

If your company uses an enterprise Box account, you may wish to consider educating your employees on the importance of not sharing the link to files or folders with others inside or outside of the company, and also to review and update your account configuration.

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations. Attorney Advertising.

© Robinson+Cole Data Privacy + Security Insider

Written by:

Robinson+Cole Data Privacy + Security Insider
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Robinson+Cole Data Privacy + Security Insider on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide