Apple, Other Box Account Users Exposed Sensitive Corporate Data: Adversis

Advertisement
By Tasneem Akolawala | Updated: 12 March 2019 17:50 IST
Highlights
  • Adversis stumbled upon large pool of sensitive data shared through Box
  • This is due to easy link creation, leaving hackers to guess them easily
  • Affected companies were advised to change their privacy settings
Apple, Other Box Account Users Exposed Sensitive Corporate Data: Adversis

Adversis says Apple, Edelmen, Amadeus data was exposed through Box

Cyber-security firm Adversis has published a paper claiming that it discovered hundreds of thousands of documents and terabytes of data exposed across hundreds of Box customers. Box is a cloud-based content management platform, and is used by several big companies like Apple, Discovery, Edelmen, Amadeus, and more. This exposure of private content is due to easy guessing or brute forcing of Box account shared document URLs, and is not a bug or vulnerability. Box has responded saying that it is "taking steps to make privacy settings more clear, better help users understand how their files or folders can be shared, and reduce the potential for content to be shared unintentionally."

Adversis says that the data that has been exposed, includes passport photos, social security and bank account numbers, high profile technology prototype and design files, employees lists, financial data, invoices, internal issue trackers, customer lists and archives of years of internal meetings, IT data, VPN configurations, and network diagrams. TechCrunch reports that companies like Amadeus, Apple, TV channel Discovery, Edelman, Herbalife, Schneider Electric, PointCare, and United Tissue Network were a part of a list of known exposed Box accounts. Amadeus, Apple, Box, Discovery, Herbalife, Edelman and PointCare have all reconfigured their enterprise accounts to prevent access to their leaking files.

The issue is mainly due to easy URLs for all the files and folders of a Box account holder. All the links that are public usually can only be accessed by users with whom the link is shared. However, if a user is successful in guessing the URL, they can access it easily, and often these links include sensitive data.

In its post, Adversis writes that Box has been prompt to call out the issue of URL guessing and recommends that administrators configure Shared Link default access to 'People in your company' to reduce accidental creation of public (open) links by users. It also recommends regular scan of shared link report, and advises users to not create public (open) custom shared links to content that is not intended for public consumption. Adversis adds that the possibility of guessing or brute forcing Box account shared document URLs was first pointed out in June last year, but gained little attention.

Advertisement

Box spokesperson Denis Roy told the publication, "We take our customers' security seriously and we provide controls that allow our customers to choose the right level of security based on the sensitivity of the content they are sharing. In some cases, users may want to share files or folders broadly and will set the permissions for a custom or shared link to public or 'open'. We are taking steps to make these settings more clear, better help users understand how their files or folders can be shared, and reduce the potential for content to be shared unintentionally, including both improving admin policies and introducing additional controls for shared links."

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: Adversis, Box, Data Threat, Apple
Advertisement
Popular Mobile Brands
  1. Samsung Galaxy S25 FE Tipped to Retain Galaxy S24 FE Rear Cameras
  2. OnePlus 13s With Snapdragon 8 Elite Chip to Launch in India on This Date
  3. Vivo S30, S30 Pro Mini, Pad 5, TWS Air 3 Launch Date, Key Features Confirmed
  4. Honor 400 Series Will Launch in China on This Date; Battery Capacity Teased
  5. New Study Challenges Fuzzy Dark Matter with Stronger Mass Constraint
  6. Android Desktop Mode Said to Debut With Android 17 on Pixel
  7. Red Dead Redemption 2 Is Reportedly Coming to Nintendo Switch 2 This Year
  8. Home Projector Market to Double In Next 4 Years: Rajeev Singh, BenQ India
  1. Sun Unleash a 600,000-Mile Filament in Fiery Eruption
  2. New Study Sets Stronger Mass Limit on Ultralight Bosonic Dark Matter
  3. NASA’s Perseverance Captures Deimos Before Dawn in Striking Martian Sky Image
  4. Huawei MateBook Fold Ultimate Design With 18-Inch Double-Layer Flexible OLED Display Launched: Price, Features
  5. Huawei Nova 14 Ultra, Nova 14 Pro, Nova 14 With 5,500mAh Battery, 100W Charging Launched: Price, Specifications
  6. Coinbase Faces Multiple Lawsuits After User Data Breach: Report 
  7. Dubai's VARA Sets June 19 Deadline for Crypto Firms to Comply With Updated Activity-Based Rulebooks
  8. Acer AI TransBuds With Ear-Hook Design Unveiled at Computex 2025
  9. Nintendo Switch 2 to Support Text-to-Speech in GameChat, VRR Support Limited to Handheld Mode
  10. Honor 400 Series China Launch Date Revealed; Confirmed to Offer Battery Upgrade Over Predecessors
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.