Findings
Every finding ranked by dollar loss. Click filters to re-sort.
Sum of per-finding ALE (mode)
AWS access key committed to shared OneNote
Page "AWS Runbook" in the Engineering Team Notebook contains an AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY pair. Notebook shared with 47 users.
1,847 credit card numbers in customers-export.csv
File contains 1,847 unique credit card numbers (PCI scope). Shared with an anonymous link that has not expired.
5 employee SSNs exposed in Q4-financials.xlsx
File contains 5 unique US SSNs in Sheet1 columns B-E. Permissions: Finance Team (18 members), anyone with link.
PHI in patient-intake-Q3.pdf (HIPAA scope)
Form contains patient names, DOBs, diagnoses, and insurance IDs for 23 patients. External guest access enabled.
Azure SQL connection string in deployment runbook
Production Azure SQL connection string with embedded password is in a broadly-shared docx.
Passport numbers in travel-authorization.xlsx
Spreadsheet contains passport numbers for 34 employees plus DOBs and home addresses.
Anonymous link on Legal/Contracts folder
Folder containing 847 executed contracts has an anonymous-access share link. Anyone with URL can read everything.