S3 bucket misconfigurations alone probably account for a sizeable fraction of all dataleaks over time, with AD misconfigurations a close second.
Things I still regularly come across:
- developers with copies of the production database on their laptop
- said laptop doesn't have an encrypted hard drive
- every developer having access to production databases, including people hired yesterday
- default userids / passwords hardcoded in firmware
- the marketing department having access to the production database in bulk
- datalakes with zero access controls that perfectly mirror the production db
- sharepoints without proper authentication storing mountains of customer data
Anyway, I could go on like this for a while. And usually the company employees are aware of these, they just haven't gotten around to plugging the holes or they were never going to unless someone told them to because it is convenient. Occasionally there is serious pushback, for instance against developers having a recent copy of the production database on their laptop is in some places considered perfectly normal.