Russian Firms Accumulate Digital Clutter: 35% of Corporate Files Unused for Years, Weak Passwords Expose Sensitive Data
Russian businesses continue to accumulate digital clutter while granting overly broad access rights across corporate storage systems. Garda, a company within IKS Holding, analyzed repositories belonging to more than 100 organizations and uncovered multiple serious concerns.
The dataset included over 157 TB of data and more than 511,000 user accounts. Approximately 35% of files had remained untouched for more than five years. Duplicate copies may account for another 35% of stored volume. In some sectors, up to one-third of the space was occupied by personal photographs, videos, archives, and other non-business content.
Paying to store this digital waste is only part of the problem. The larger the number of uncontrolled copies scattered across folders and resources, the harder it becomes to determine where confidential information resides and who can access it.
Access management practices also raised alarms. More than 33% of accounts used critically weak passwords or passwords that had not been rotated for a long time. Auditors discovered numerous contractor and temporary employee accounts inactive for over 90 days. In large organizations, direct permissions issued outside security groups were common. Folders with wide access rights often contained passport scans, client registries, database exports, and other sensitive documents.
Garda concludes that manual remediation of such volumes is no longer practical. The company advises organizations to regularly inventory and classify information, manage access centrally, and automate the full data lifecycle from creation to deletion.
Related articles
Taiwan Man Uses Robot Vacuum Camera to Prove Wife's Affair, Wins Compensation but Receives Prison Sentence for Illegal Recording
A resident of Taiwan suspected his wife of infidelity after discovering a stranger's toothbrush in their countryside home. He reviewed footage from a parking lot camera and later accessed the live feed of their robot vacuum cleaner through its mobile application, capturing intimate recordings without consent. The man preserved the video evidence and successfully sued for breach of marital rights, receiving approximately $19,000 in compensation. His wife filed a counterclaim, arguing that the recordings violated her right to privacy because the device's sensors and indicators did not clearly indicate active surveillance. Although the footage was accepted in the civil case, the court ruled that the illegal method of obtaining it outweighed marital obligations, prioritizing personal privacy protections. The husband was sentenced to five months in prison and fined 150,000 Taiwanese dollars, representing 30 percent of his awarded compensation.
Apple Updates Private Relay Domain for Sign in with Apple: Why Email Cannot Serve as Account Identity
Apple announced that new Private Relay addresses for Sign in with Apple will use the private.icloud.com domain starting later in 2026, while existing privaterelay.appleid.com addresses will continue functioning without interruption. The change highlights a deeper architectural issue: many applications incorrectly treat email addresses returned by Apple as stable identifiers rather than transient contact channels. Proper implementation requires separating the signed identity token, the verified subject claim, and the optional email relay address into distinct data models. Developers must validate the full identity token on the server, including signature, issuer, audience, nonce, and expiration, before linking any Apple identity to an internal account. Using provider and subject pairs as the unique key prevents duplicate accounts, accidental merges, and broken logins when relay domains or email claims change. The article provides concrete recommendations for data models, token verification boundaries, and test cases that remain resilient to future Apple updates.
Step-by-Step Guide to Removing Personal Data from Search Engines, Databases and Social Networks
The guide provides a practical seven-step checklist for individuals seeking to reduce their digital footprint by removing personal information from websites, search engines, and social platforms. It emphasizes starting with a 20-minute audit to compile exact URLs rather than vague requests, followed by direct contact with site owners under Russia's 152-FZ personal data law. Subsequent steps cover submissions to Yandex and Google for de-indexing, manual cleanup of old social media accounts, handling of phone numbers in caller ID services, and removal from directories and review sites. The process includes templates for formal requests, timelines for responses, and escalation paths to Roskomnadzor when operators fail to comply. Special attention is given to leaked databases, where technical removal is impossible, and to web archives such as Internet Archive that require specific legal justifications. The full cycle is estimated at two months, with quarterly maintenance recommended to sustain results.
telEgo Combines MTProxy and WEB Proxy on Single Port 443 with TLS Fronting
telEgo, a Go-based Telegram MTProxy implementation using the gnet network engine, now supports all four WEB proxy transport modes alongside traditional MTProxy connections on the same public port 443. The solution allows FakeTLS with ee secrets, Obfuscated2 with dd secrets, and WEB carriers including https, https-lanes, websocket, and websocket-lanes without requiring separate ports or secret changes. telEgo performs handshake detection, forwards ordinary TLS traffic to Nginx on a private port using PROXY protocol v2, and routes authenticated WEB streams back to the internal MTProxy backend. The setup uses Docker Compose with separate containers for telEgo, Nginx, and certificate management via Certbot, keeping ports 8080, 8443, and 8444 internal. Existing MTProxy links continue to function while new WEB proxy links become available for Telegram Desktop. The configuration supports Prometheus metrics, connection limits, and automatic certificate renewal through systemd timers.