The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Neo Security reported in October 2025 that an EY-associated 4 TB SQL Server backup was publicly reachable. EY told TechRadar Pro that it had remediated a potential exposure and that no client information, personal data, or confidential EY data was impacted. The available reporting does not confirm that anyone else accessed or copied the file.
What was reportedly exposed?
Neo Security said a researcher found a publicly reachable SQL Server backup file associated with EY while doing low-level tooling work. The firm reported the file was 4 TB and said its researcher inspected a small sample, identified it as a database backup, then stopped investigating and contacted EY. This is Neo Security’s account of the discovery, not an independently published forensic report. Neo Security’s incident account and TechRadar Pro’s report both describe a backup file, not a confirmed release of its contents.
The 4 TB figure is the reported size of the file, according to Neo Security in 2025. It is not a count of records, customers, or people affected.
Does the backup prove company secrets were stolen?
No. A SQL Server backup can contain database structure, stored procedures, and data, including sensitive values saved in tables. Neo Security listed API keys, session tokens, credentials, and service-account passwords as examples of what a database backup might contain. The reporting does not provide a verified inventory of this particular file, so those examples should not be treated as confirmed contents.
#1 Best Overall
Neo Security said it did not download the full backup. The sources do not establish how long the file was publicly reachable, whether an unauthorized third party accessed it, or whether anyone copied data. A file being reachable without authorization controls creates a real exposure risk, but reachability alone does not prove theft or compromise.
What did EY say about the incident?
EY told TechRadar Pro: “Several months ago, EY became aware of a potential data exposure and immediately remediated the issue.” EY also said: “No client information, personal data, or confidential EY data has been impacted. The issue was localized to an entity that was acquired by EY Italy and was unconnected to EY global cloud and technology systems.” These are EY’s statements as reported by TechRadar Pro; the available coverage does not include independent evidence verifying impact or scope.
Rank #2
How quickly was it addressed?
Neo Security said EY acknowledged its report and that the issue was fully triaged and remediated one week later. That is Neo Security’s account of the response timeline, not an independently established measure of how long the file had been exposed. The sources do not identify when public access began or ended.
What remains unknown?
- The exact exposure window: the reviewed reporting does not establish when the backup first became publicly reachable or when it was secured.
- Whether anyone other than the reporting researcher accessed or downloaded it: no confirmed third-party access or exfiltration is reported.
- What the file contained: no verified inventory of the database contents is provided.
- Whether there was measurable harm: no independently verified count of affected records or people is reported.
- The technical cause: the reporting does not establish the configuration or other root cause that made the file reachable.
What would establish the impact of an exposure?
In a typical investigation, responders would examine the scope of the affected storage object and business entity, determine the start and end of public access, review access logs and forensic indicators for evidence of downloads, and document remediation. Where warranted, they would also consider credential rotation and notification decisions. These are general investigative questions, not actions confirmed in the reporting about EY.
Rank #3
The reports date to 29–30 October 2025 and concern an entity associated with EY Italy. They do not establish a broader incident involving EY’s global cloud or technology systems; EY specifically said the issue was unconnected to those systems.
Quick Recap
Best Value
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

