
Cybersecurity Researcher Jeremiah Fowler uncovered a non-password-protected CRM database containing millions of records belonging to the global B2B CRM provider Really Simple Systems.
The exposed database comprised over 3 million records, including documents related to internal invoices, communications, and customer CRM files. These cloud-based customer relationship management systems are crucial for managing customer interactions and storing vital business data.
Within the database, numerous folders primarily housed documents associated with individual companies and their customers. Additionally, it contained shared images, invoices, templates, and other internal records owned by Really Simple Systems.
The database featured 2,565,602 .dat files, 50,242 image files, and 101,290 invoices, potentially exposing customer names, addresses, and CRM plan details. Fowler observed various documents from organizations worldwide, including small businesses and well-known global entities in the USA, UK, Australia, and multiple EU countries. The exposed records included sensitive information such as medical records, identification documents, real estate contracts, credit reports, legal documents, tax records, non-disclosure agreements, disability claims, and confidential child psychological examination documents.
Remarkably, these records were accessible to anyone with an internet connection, raising concerns about data security and privacy. Upon notifying Really Simple Systems, Fowler received a response acknowledging the issue. While one folder related to an educational platform was promptly secured, others remained accessible for several days before restriction.
It remains unclear how long the data was exposed or if any unauthorized access occurred before security measures were enacted. Fowler does not allege any malicious intent behind the data exposure.
According to Wikipedia, Really Simple Systems CRM boasts over 18,000 users, including prestigious organizations such as the Royal Academy, the Red Cross, the NHS, IBM, and numerous small and medium-sized enterprises.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543