Pharmaceutical giant AstraZeneca has blamed user error for leaving a list of credentials online for more than a twelvemonth that exposed access to sensitive patient data.
Mossab Hussein, chief security officer at cybersecurity startup SpiderSilk, told TechCrunch that a developer left the credentials for an AstraZeneca internal server on code sharing site GitHub in 2021. The credentials allowed access to a trial Salesforce cloud environment, often used by businesses to manage their customers, but the test environment contained some patient data, husain said.