An unsecured server belonging to Logezy, a UK-based workforce management and staffing solution, has exposed a trove of sensitive documents online, including IDs, contracts, and financial records. The breach, discovered by cybersecurity researchers at vpnMentor, highlights the risks businesses face by misconfigured cloud-based storage solutions.
In April 2025, cybersecurity researcher Jeremiah Fowler discovered an unprotected database with 7,975,438 files measuring a combined 1.1 TB connected to Logezy. Although the company quickly secured the server after it was contacted, the breach remained open and accessible without authentication at the time of discovery, putting sensitive data at risk of theft, fraud, and other abuse.
“Although the records belonged to Logezy, it is not known if the database was owned and managed directly by them or by a third-party contractor,” Fowler’s report reads. “It is also not known how long the database was exposed before I discovered it or if anyone else may have gained access to it. Only an internal forensic audit could identify additional access or potentially suspicious activity.”
The database contained highly sensitive personal and employment data in PDF and image formats, including:
“The database also contained 656 directory entries indicating different companies, most of which were healthcare providers, recruiting agencies, or temporary employment services,” Fowler said.
The files dated as far back as 2014, indicating a long-term accumulation of sensitive documents stored without adequate protection.
The level of data exposed in this breach poses serious threats, including:
If you suspect your information may have been exposed:
tags
Alina is a history buff passionate about cybersecurity and anything sci-fi, advocating Bitdefender technologies and solutions. She spends most of her time between her two feline friends and traveling.
View all postsApril 03, 2025
March 12, 2025
February 20, 2025
February 11, 2025