KPMG found leaking data after issuing data leak report

By on
KPMG found leaking data after issuing data leak report

Printers, internal directories found.

Sensitive data has been found on KMPG's website soon after the consultancy released a report revealing blue chip companies doing the same.

Security researcher Robin Wood found 400 email addresses, 164 users and 112 PC names along with printers, software versions and  "quite a lot of internal directories" on the US KPMG site.

He said the consultancy was running IIS servers on version 6, two versions out of date.

KPMG had earlier reported that every company on the FTSE 350 list had left employee usernames, email addresses and sensitive internal file location information online.

It said an average of 41 usernames, 44 email addresses and five sensitive internal file locations were available from each company.

A spokesperson for the consultancy said it audited its own site along with those in the report.

"We recognise that many websites provide some level of data leakage and with this in mind, the purpose of our report is to highlight concerns so they can be dealt with, rather than highlight individual weak spots."

This article originally appeared at

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, UK edition
In Partnership With

Most Read Articles

Log In

Username / Email:
  |  Forgot your password?