Canadian Cyber Security Journal
SOCIAL:
Filed under: TechTalk

Veeam Left a Marketing Database Open for Days — What Canadian Backup Customers Should Check

What Happened

Independent researcher Bob Diachenko found a MongoDB database belonging to backup and data-protection vendor Veeam sitting open on Amazon Web Services with no authentication. Diachenko located the roughly 200GB database using Shodan on September 5 and found an estimated 445 million records inside, most appearing to be duplicate entries built from customer and partner names, emails, countries, and marketing attributes collected between 2013 and 2017. Diachenko says he tried to reach Veeam directly after finding the database and received no response. The database stayed open until September 9, when Veeam locked it down, days after the initial outreach. Veeam has not disclosed how long the server sat exposed before Diachenko found it. Full details are in Dark Reading’s report.

Why This Matters for Canadian Organizations

Veeam holds a large share of the Canadian backup and disaster-recovery market, from small IT shops to large enterprises and government contractors relying on it to protect data covered by PIPEDA and provincial privacy law. This incident did not touch backup data itself, only an old marketing database, and this distinction matters. But it shows a pattern security teams see again and again: a vendor’s peripheral system, not its core product, ends up as the point of failure, and a slow response to external researcher outreach turns a fixable misconfiguration into a multi-day exposure window. A Canadian organization treating a vendor’s security reputation as a reason to skip its own vendor risk review is relying on an assumption this incident undercuts.

What to Do

Ask your backup vendor, and any vendor holding customer contact data, whether it has a published vulnerability disclosure or bug bounty contact responding within hours, not days. Review your own data retention practices for old marketing records no longer needed, since data from 2013 has no business reason sitting in an internet-facing database in 2026. Treat vendor breach notifications as a trigger to confirm your production backups and access credentials remain unaffected, even when the vendor states the exposure was isolated.

Enjoy this article? Don’t forget to share.