
Millions of healthcare workers in the United Kingdom may have had their personal information exposed following the discovery of an unsecured online database. The incident involves nearly eight million files, including highly sensitive documents such as national insurance numbers, work authorization records, government-issued IDs, certificates, timesheets, and electronic signatures.
The breach was uncovered by cybersecurity researcher Jeremiah Fowler, who found the 1.1-terabyte database accessible online without password protection. The archive contained 7,975,438 files, many in image and PDF formats, and appeared to include data tied to at least 656 organizations. The majority of those entries were linked to healthcare providers, staffing agencies, and temporary employment services.
Fowler attributed the database to Logezy, a UK-based software firm that provides employee management and tracking solutions. After being alerted to the exposure, Logezy reportedly secured the database “shortly after” being notified.
It remains unclear how long the database was exposed or whether it was managed directly by Logezy or hosted by a third-party vendor. Furthermore, without a comprehensive forensic investigation, there is no way to determine whether any malicious actors accessed or downloaded the information during the exposure window.
Databases like the one found are considered “low-hanging fruit” for cybercriminals, as they often require no sophisticated techniques—such as phishing or malware—to access. Once obtained, the exposed data can be exploited in a wide range of fraudulent activities, including identity theft, financial scams, and unauthorized transactions.
Fowler, who regularly scans the internet for unsecured databases using tools like Shodan, has uncovered numerous similar incidents in the past. Previous discoveries include exposed records from ClickBalance (over 750 million entries), DM Clinical Research (over one million), and ServiceBridge (31 million), underscoring the frequency and scale of such security lapses.
Logezy has not yet disclosed whether it plans to notify affected individuals or regulatory bodies, nor has it provided details on how the exposure occurred. Given the nature of the data involved, experts warn that those who have used Logezy’s services should monitor their credit reports and account activity closely for any signs of misuse.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543