Encryption provider for Sony leaks data for over a year

A vulnerability in encryption platform ENC Security has exposed data for over a year

Add bookmark
Encryption provider for Sony leaks data for over a year

A server at encryption services company ENC Security, which serves more than 12 million customers including Sony and Lexar, has been leaking data since 2021.

An investigation by technology news site Cyber News into the Netherlands-based security provider has revealed a flaw in its software which has caused it to leak configuration and certificate files from May 27, 2021 to November 9, 2022.

The data stored inside the vulnerable server included a range of information used to authenticate customers’ identities. These included HMAC message authentication codes, Simple Mail Transfer Protocol (SMTP) credentials, API keys used for licensing payment and email marketing via Mailchimp, access keys for payment platform Adyen and public and private keys stored in.pem format.  

If accessed by unauthorized parties, this data could be exploited by malicious parties for a range of threat vectors, including phishing and ransomware. It could also be used to expose confidential customer information.

An ENC Security spokesperson said to Cyber News that the company “take[s] the security and protection of [its] data seriously” and that findings like the vulnerability are “researched and remediated with appropriate measures [taken]”.

The vulnerability, which according to ENC Security was due to configuration issues with a third-party supplier, was resolved soon after the company was alerted to it. 


Upcoming Events

Automotive Cyber Security, Connectivity & SDV Week 2025

18th - 20th November, 2025

Van der Valk Hotel Berlin Brandenburg, Germany

Automotive Cyber Security, Connectivity & SDV Week 2025

Digital Identity Week

1st - 2nd September 2026

Sydney, Australia

Digital Identity Week

Latest Webinars

From Dependencies to Defences: Navigating Software Supply Chain Security

2025-09-24

11:00 AM - 12:00 PM SGT

Learn how to defend your software supply chain from dependency threats and build resilient security...

Unpacking global regulatory frameworks to enhance third-party operational resilience

2024-11-14

11:00 AM - 12:00 PM EST

Join this webinar to explore the resilience-focused requirements of DORA, NIS2 and other global regu...

Preventing financial and reputational risk with process intelligence

2024-05-23

11:00 AM - 12:00 PM EDT

Learn how to manage risk stemming from poorly controlled processes in a collaborative way

Recommended