This site uses cookies. By continuing to browse this site you are agreeing to our use of cookies. Find out more.X

Exclusive: Reverse assessment reveals KPMG's publicly accessible data

Share this article:

Publicly available information has been found on auditor and consultancy KPMG, on the day it released a report on the FTSE 350's security flaws.

In its report, KPMG said that according to research and simulated attacks carried out by its cyber response team, every company on the FTSE 350 list left employee usernames, email addresses and sensitive internal file location information online. It found that on average, 41 usernames, 44 email addresses and five sensitive internal file locations were available for each company. 

In an email to SC Magazine, security researcher Robin Wood said that running two public, commonly available tools against the KPMG website achieved over 400 email addresses, 164 users, 112 PC names and quite a lot of internal directories. He also said that there were a handful of printers accessible, as well as software versions. “A quick check of www.us.kpmg.com showed they are running IIS 6.0 while the latest is version 8,” he said.

He confirmed that this was public information, and he gathered information that was available without hacking tactics. He showed SC a 62-page document of these details. 

A spokesperson for KPMG said that the report was not designed to throw stones, but demonstrate how easy it is for hackers to get hold of information that can be used against companies.

The company said in a statement: “As you might expect, KPMG put its own site through the same examination as we did other sites. We recognise that many websites provide some level of data leakage and with this in mind, the purpose of our report is to highlight concerns so they can be dealt with, rather than highlight individual weak spots. We were careful not to reveal specific weaknesses of any company as it would be inappropriate to do so.” 

KPMG said that as a partnership, it does not appear on the FTSE 350 Index and was not evaluated as part of its assessment. However it put its own site through the same examination as we did other sites.

 

Share this article:

SC webcasts on demand

This is how to secure data in the cloud


Exclusive video webcast & Q&A sponsored by Vormetric


As enterprises look to take advantage of the cloud, they need to understand the importance of safeguarding their confidential and sensitive data in cloud environments. With the appropriate security safeguards, such as fine-grained access policies, a move to the cloud is as, or more, secure than an on-premise data storage.


View the webcast here to find out more

More in News

Russian government promises £60k bounty to Tor hackers

Russian government promises £60k bounty to Tor hackers

The Russian Ministry of Internal Affairs (MVD) is offering a 3.9 million ruble (approximately £64,600) reward to anyone who can find a way of identifying and tracking users of the ...

UK watchdog warns firms on Big Data risks

UK watchdog warns firms on Big Data risks

UK watchdog The Information Commissioner's Office (ICO) has released a comprehensive report into big data which warns companies that their data analytics activities must adhere to existing data protecting laws.

4% of Googlebots are fake and can launch attacks

4% of Googlebots are fake and can ...

Admins' fear of damaging their SEO gives malicious search engine bots a 'VIP pass' into sites.