- What happened: the misconfiguration that exposed everything
- The technical issue: what is a cloud misconfiguration
- The immediate impact: who pays the price for the mistake
- What nobody is saying: the hidden risk in SMEs
- What to do now: top priorities for businesses
- Outlook: security as a competitive edge
In May 2026, a serious security incident hit a hotel check-in system. The responsible tech company had set up their cloud storage as public. As a result, over a million passports and driver's licenses were accessible to anyone, with no password at all.
However, the problem doesn't just concern the hospitality industry. In fact, cloud misconfiguration is now one of the main causes of data breaches across all sectors. Therefore, any company using cloud infrastructure — even SMBs — is potentially exposed to similar risks. In particular, anyone entrusting data management to third-party providers must regularly check their access settings.
We at SHM Studio we are keeping a close eye on these incidents. We believe that digital infrastructure security is an operational priority, not something to put off. So, this case is a great opportunity to audit your own cloud setups. In short: a misconfiguration can cost way more than investing in security beforehand.
What happened: the misconfiguration that exposed everything
May 15, 2026, TechCrunch reported a classic case of a data breach in the hotel industry. A tech company that handles hotel check-in systems had set up its cloud storage to be public. Anyone, with zero credentials, could freely access the stored data.
The result was devastating. Over one million ID documents — passports and driver's licenses — were visible and downloadable by anyone with the correct URL. No sophisticated attack was necessary. You just had to know where to look.
So, this isn't a hack in the traditional sense of the word. It's a human configuration mistake, known in the industry as cloud misconfiguration . However, the consequences for affected users are identical to those of an intentional breach.
The technical issue: what is a cloud misconfiguration
A cloud misconfiguration it happens when access settings for a cloud service are configured incorrectly. In this case, a storage bucket — likely on AWS S3 or a similar service — was set to public access instead of private.
This type of mistake is surprisingly common. According to Gartner, nearly all breaches in cloud environments are due to misconfigurations on the client or vendor side, not vulnerabilities in the cloud provider itself.
Plus, the growing complexity of cloud setups—multi-cloud, microservices, scattered storage—makes messy misconfigurations way more likely. Every new service you spin up is a potential weak spot. As a result, your attack surface gets bigger right along with your company's digital growth.
Specifically, identity data like passports and ID cards are among the most sensitive information. Their handling is regulated by the GDPR in Europe. Therefore, an exposure like this brings obligations to notify authorities and risks major fines.
The immediate impact: who pays the price for the mistake
The fallout from this incident hits on multiple levels. First off, the end users: the hotel guests whose docs were exposed. For them, the real risk is identity theft, document cloning, and fraudulent use of their info.
Next up, the tech company in charge is gonna face regulatory investigations. Over in Europe, GDPR has fines up to 4% of global yearly turnover for foul-ups this major. Plus, the vendor's reputation takes a hit that's pretty much impossible to undo.
Lastly, the hotels using the system are indirectly caught in the middle. Even though the screw-up wasn't on them, their guests were put at risk. So, the trust with their customers takes a real hit. This highlights a key takeaway: security responsibility doesn't just completely shift over to the tech vendor.
As Harvard Business Review also points out, cyber resilience requires shared governance between the company and its vendors. Relying on a contractual SLA is not enough.
What nobody is saying: the hidden risk in SMEs
Public chat about these breaches usually focuses on big corporations. But small businesses are often way more vulnerable. They've got fewer resources to keep an eye on cloud setups and rely more heavily on outside vendors without checking their security game.
Many small and medium-sized Italian businesses have moved to cloud solutions over the past few years. Often they did it in a rush, without a structured process of security review . As a result, misconfigurations can remain invisible for months or years, until they are discovered — by a researcher, a journalist, or worse, a malicious actor.
We at SHM Studio We see this happen all the time. Companies digitize critical processes—from customer management to document collection—without ever running an access settings audit. The issue isn't the cloud tech itself. The issue is a lack of governance.
Plus, the hotel check-in deal is about one specific industry. But the exact same pattern pops up in all sorts of fields: law and accounting firms, clinics, real estate agencies, e-commerce sites. Basically anywhere sensitive data gets scooped up and stored on cloud setups.
What to do now: top priorities for businesses
This episode offers a practical opportunity to review your security practices. The actions to consider are clear and do not require extraordinary investments. They do, however, require method and consistency.
- Cloud configuration audits: make sure that all storage buckets, databases, and exposed services have correct access settings. Specifically, no asset containing personal data should be publicly accessible without authentication.
- Reviewing vendor contracts: Service Level Agreements need to include clear clauses on data security. The vendor must take responsibility for the settings they manage.
- Implementing the principle of least privilege: every user and every service should only access data strictly necessary for their function.
- Continuous monitoring: tools of cloud security posture management (CSPM) allow you to automatically spot misconfigurations before they turn into a problem.
- Staff training: many misconfigurations stem from a lack of awareness. A basic cloud security training program significantly cuts down the risk.
For SMEs that manage customer data via digital platforms, a useful starting point is reviewing their web infrastructure and integrations with third-party cloud services.
Outlook: security as a competitive edge
Looking ahead to the coming months, we can expect to see more and more attention from European regulators. The Italian Data Protection Authority and agencies in other member states are ramping up inspections. So, GDPR compliance isn't just a theory anymore.
At the same time, customers—whether B2B or B2C—are getting way more clued-in about the risks of handling their data. A business that shows it takes security seriously gains a real, measurable boost to its reputation. On the flip side, a public breach can wipe out years of built-up trust in an instant.
In this context, investing in digital infrastructure security is not just a defensive necessity. It is a strategic choice. Companies that integrate security into their operating model — from AI data management to the digital presence — they build a stronger foundation for growth.
Anyone wanting to dive deeper into the technical implications of secure cloud architectures can refer to the research by McKinsey Digital Center , which shows how cybersecurity is becoming a competitive edge even for mid-sized companies.
For Italian SMEs looking to kick off an assessment of their digital security posture, the team at SHM Studio is available for a discussion . Just like anyone wanting to bake security into their strategies for SEO , content and digital advertising . Finally, those who manage campaigns on social platforms may also find it useful to check advertising account access settings, such as those related to LinkedIn campaigns .
The SHM Studio blog will continue to monitor how these issues unfold. Because digital security isn't a separate chapter from your business strategy. It's a core part of it.
Related articles
Discover more articles exploring similar topics, selected to offer you a more complete and stimulating perspective. Each piece of content is carefully chosen to enrich your experience.