Security News > 2021 > March > Hobby Lobby Exposes Customer Data in Cloud Misconfiguration

Hobby Lobby Exposes Customer Data in Cloud Misconfiguration
2021-03-23 19:46

"The Hobby Lobby incident is the latest example of why we need to take public cloud threat vectors so seriously," said Douglas Murray, CEO at Valtix, told Threatpost.

"In 2020, spend in public cloud exceeded spend in on-prem data centers for the first time. The hackers are doing their own version of 'lift and shift' and are aggressively moving to where the market is going. Just as concerning is that for every Hobby Lobby like leak that we learn about, there is another that goes undetected."

"Misconfigured cloud resources are frequently the cause of data breaches like this one," he told Threatpost.

"Organizations that have transitioned to the cloud have massive infrastructure that spans thousands of host servers and other services. Amazon's S3 service is the base data storage offering for AWS, which means it's simple to set up and integrate S3 buckets into cloud infrastructure. Unfortunately, that simplicity they offer and the speed at which organizations scale these services up and down oftentimes means the configuration of these buckets is overlooked and the data inside is left exposed."

"Advanced cloud access security broker technology helps secure access to these resources," he said.

"Coupling CASB with a security posture management tool ensures secure access and configuration of cloud infrastructure. Cloud providers offer countless supporting services and integrations that help teams build a well-architected infrastructure. Leveraging these services should be done in tandem with security teams to ensure there aren't any misconfigurations that leave data exposed or violate compliance policies."


News URL

https://threatpost.com/hobby-lobby-customer-data-cloud-misconfiguration/164980/