KPMG found leaking data after issuing data leak report

By

Printers, internal directories found.

Sensitive data has been found on KMPG's website soon after the consultancy released a report revealing blue chip companies doing the same.

KPMG found leaking data after issuing data leak report

Security researcher Robin Wood found 400 email addresses, 164 users and 112 PC names along with printers, software versions and  "quite a lot of internal directories" on the US KPMG site.

He said the consultancy was running IIS servers on version 6, two versions out of date.

KPMG had earlier reported that every company on the FTSE 350 list had left employee usernames, email addresses and sensitive internal file location information online.

It said an average of 41 usernames, 44 email addresses and five sensitive internal file locations were available from each company.

A spokesperson for the consultancy said it audited its own site along with those in the report.

"We recognise that many websites provide some level of data leakage and with this in mind, the purpose of our report is to highlight concerns so they can be dealt with, rather than highlight individual weak spots."

This article originally appeared at scmagazineuk.com

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, UK edition
Tags:

Most Read Articles

Palo Alto Networks in talks to buy CyberArk

Palo Alto Networks in talks to buy CyberArk

Gov to encourage vuln research, puts insurers and NFPs on notice

Gov to encourage vuln research, puts insurers and NFPs on notice

"Scattered Spider" evolves with new ransomware and social engineering tactics

"Scattered Spider" evolves with new ransomware and social engineering tactics

Allianz Life says majority of US customers' data stolen in hack

Allianz Life says majority of US customers' data stolen in hack

Log In

  |  Forgot your password?