Apple, Other Box Account Users Exposed Sensitive Corporate Data: Adversis

Advertisement
By Tasneem Akolawala | Updated: 12 March 2019 17:50 IST
Highlights
  • Adversis stumbled upon large pool of sensitive data shared through Box
  • This is due to easy link creation, leaving hackers to guess them easily
  • Affected companies were advised to change their privacy settings

Adversis says Apple, Edelmen, Amadeus data was exposed through Box

Cyber-security firm Adversis has published a paper claiming that it discovered hundreds of thousands of documents and terabytes of data exposed across hundreds of Box customers. Box is a cloud-based content management platform, and is used by several big companies like Apple, Discovery, Edelmen, Amadeus, and more. This exposure of private content is due to easy guessing or brute forcing of Box account shared document URLs, and is not a bug or vulnerability. Box has responded saying that it is "taking steps to make privacy settings more clear, better help users understand how their files or folders can be shared, and reduce the potential for content to be shared unintentionally."

Adversis says that the data that has been exposed, includes passport photos, social security and bank account numbers, high profile technology prototype and design files, employees lists, financial data, invoices, internal issue trackers, customer lists and archives of years of internal meetings, IT data, VPN configurations, and network diagrams. TechCrunch reports that companies like Amadeus, Apple, TV channel Discovery, Edelman, Herbalife, Schneider Electric, PointCare, and United Tissue Network were a part of a list of known exposed Box accounts. Amadeus, Apple, Box, Discovery, Herbalife, Edelman and PointCare have all reconfigured their enterprise accounts to prevent access to their leaking files.

Advertisement

The issue is mainly due to easy URLs for all the files and folders of a Box account holder. All the links that are public usually can only be accessed by users with whom the link is shared. However, if a user is successful in guessing the URL, they can access it easily, and often these links include sensitive data.

In its post, Adversis writes that Box has been prompt to call out the issue of URL guessing and recommends that administrators configure Shared Link default access to 'People in your company' to reduce accidental creation of public (open) links by users. It also recommends regular scan of shared link report, and advises users to not create public (open) custom shared links to content that is not intended for public consumption. Adversis adds that the possibility of guessing or brute forcing Box account shared document URLs was first pointed out in June last year, but gained little attention.

Advertisement

Box spokesperson Denis Roy told the publication, "We take our customers' security seriously and we provide controls that allow our customers to choose the right level of security based on the sensitivity of the content they are sharing. In some cases, users may want to share files or folders broadly and will set the permissions for a custom or shared link to public or 'open'. We are taking steps to make these settings more clear, better help users understand how their files or folders can be shared, and reduce the potential for content to be shared unintentionally, including both improving admin policies and introducing additional controls for shared links."

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Adversis, Box, Data Threat, Apple
Advertisement
Popular Mobile Brands
  1. New OTT Releases This Week : Dhurandhar 2, Maa Behen, The Pyramid Scheme, and More
  2. Samsung May Bring Back Snapdragon-Powered Galaxy Z Flip With Z Flip 8
  3. OnePlus 15, Nord 6, Pad 4 Receive Discounts During Community Sale 2026
  4. OnePlus Turbo 6X, OnePlus Turbo 6X Pro Key Specifications Teased
  5. Redmi Turbo 5 India Launch Date Revealed as Company Confirms Key Specs
  6. OnePlus Might Soon Launch a Flagship Phone With 2K Display and a 240Hz Refresh Rate
  7. Tecno Pova 8 to Launch in India With 8,000mAh Battery on This Day
  8. Xiaomi Pad 8 Price Increased: Here's How Much It Costs Now
  9. One UI 9 Testing Said to Be Underway for Samsung Galaxy S25 Series
  1. Sahara Meteorite May Be Fragment of a Lost Moon-Sized World, Study Suggests
  2. OpenAI Introduces Smarter ChatGPT Memory, Adds Dreaming Architecture
  3. Tecno Pova 8 India Launch Date Announced; Battery Size, Design, Colour Options Teased
  4. Samsung Reportedly Starts Internal Testing of Android 17-Based One UI 9 for Galaxy S25 Series
  5. Bybit Lists Western Union’s USDPT Stablecoin for Trading and Transfers
  6. Xiaomi Pad 8 Price Hiked in India: Here’s How Much It Costs Now
  7. Instagram Reels Influencing Nearly Half of Purchase Decisions in India, Meta Study Claims
  8. OnePlus Turbo 6X, OnePlus Turbo 6X Pro Colour Options, Price Range, Key Specifications Teased
  9. Sattendru Maarudhu Vaanilai Now Streaming Online: Where to Watch Jai’s Romantic Thriller Movie
  10. Asics GEL-Kayano 33 Launched in India With New Stability Tech, FluidSupport System
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.