Cybersecurity Research

Exposed Web Page Leaked Sensitive Data at a Fortune 500 Firm, and Only One Tool Noticed

Wiz Research · 8 Oct 2026
Key Takeaway Regularly check your business from the outside, as an attacker would, to find out which pages and services expose sensitive data to the public internet, rather than relying only on inventories of where your data is stored.

A Fortune 500 financial services company had a public web page quietly serving sensitive data tied to one of its business units. There was no breach alert and no failed control, just an exposure sitting in the open. According to Wiz Research, the company said that in the past this kind of problem would have gone unnoticed for some time, and that Wiz Red Agent was the only tool in its security stack that identified it.

The customer said the finding was easy to understand at a glance, that its severity was categorised correctly, and that a summary of what was exposed meant staff did not need to audit the page at length. Wiz argues that the pace of modern development makes this kind of check essential. It is now easy to spin up a new agent or connect data to an external service, and each new integration widens the attack surface. Static scans and periodic audits struggle to keep up.

Wiz also explains why other tools may have missed the page. Traditional data security tools look from the inside out: they crawl datastores, scan for sensitive records and build an inventory. That tells you what data exists, but not whether it can be reached from the public internet. The core questions remain: where is your sensitive data, who can reach it from outside, and what could an attacker do with it right now?

data exposure attack surface Wiz financial services external visibility
Regulated in financial services? APRA CPS 220, 230 and 234, in plain language ->

Summarised by CISO AI from Wiz Research, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.