Fintech left root database credentials and master AWS keys in a weakly protected spreadsheet
Fintech firm stored critical database credentials in a weakly protected spreadsheet due to internal disagreements, creating a security vulnerability.
Jason Kwon ·

A financial technology firm stored root database credentials and master AWS IAM keys in a spreadsheet on a company-wide intranet, creating a major internal security risk despite broader spending on security controls.
The file was plainly labeled “Prod_DB_Root_Creds_DO_NOT_SHARE.xlsx” and protected only by a guessable password format that combined the company name and the current year, according to the account. The spreadsheet was accessible via an internal SharePoint folder that any employee could reach.
The lapse stemmed from an unresolved dispute between the internal DevOps team and an external database administration team over which enterprise password manager to use. As a stopgap, the teams placed high-privilege secrets in the spreadsheet, and the document reportedly remained in place for eight months.
The episode illustrates how governance and process failures can undermine technical security investments. It also runs counter to core cybersecurity practices such as least-privilege access and limiting distribution of high-privilege credentials.