Databases remain one of the primary targets for cyberattacks. They hold an organization’s most sensitive information: patient data, formulas, production histories, financial information, or customer personal data. In the digital economy, information is power, and protecting it is no longer optional.
In this article, we explore the most common incidents of recent years and how database protection evolved in 2025, helping you reduce risks and make better cybersecurity decisions in 2026.
Hundreds of ransomware and data leak incidents targeting corporate databases directly or indirectly are recorded every year, resulting in economic, regulatory, and reputational impacts that are difficult to manage. Recently, major cyberattacks worth summarizing have been detected:
With the enforcement of the NIS 2 Directive in the European Union, many companies—including SME suppliers in critical sectors—face new cybersecurity obligations, strict notification deadlines, and relevant penalties for non-compliance. In this context, having a coherent, updated database security strategy aligned with regulations is key to reducing risks and ensuring business continuity.
The sensitive information of most companies is stored in database management systems: SQL Server, Oracle, MySQL, PostgreSQL, cloud databases (Snowflake, Azure SQL, AWS RDS, BigQuery, etc.). Attackers look specifically for these repositories because they contain everything needed to extort, steal intellectual property, or commit fraud.
To achieve this, they mainly exploit:
For years, the strategy relied on building a "castle" around systems: firewalls, IDS/IPS, antivirus. But in 2025, the perimeter became blurred: we work remotely, use SaaS, multi-cloud, and external providers who also handle our data.
Recent cases like Snowflake, Santander, or El Corte Inglés show that protecting the internal network is no longer enough: we must assume data can be scattered across multiple platforms and third parties.
Therefore, database security must shift from "protecting the moat" to protecting data and identities wherever they are, under a Zero Trust approach.
Beyond classic vulnerabilities, today we must keep in mind:
1. Misconfigured cloud and multi-cloud environments
Many organizations moved their databases to the cloud for flexibility and scalability. However, incorrect configurations, lack of MFA (multi-factor authentication), or exposed access keys in code repositories can open the door to massive data leaks.
The Snowflake case demonstrated how stolen credentials from malware and environments lacking multi-factor authentication or additional controls allow an attacker to pivot across multiple databases hosted on the same platform, affecting dozens or hundreds of organizations at once.
It is common for a single organization to have data scattered across multiple providers (IaaS, PaaS, SaaS) and regions, complicating data governance and protection without unified policies and tools.
More and more incidents reach companies through their providers. A security flaw in a third party with access to our databases or systems can become the "weak link" opening the door to attackers.
The 2024 Santander incident (where an external provider's database was accessed without authorization) and the 2025 El Corte Inglés attack are clear examples of how a third party can become the entry point to critical information.
This affects integrators, software providers, hosting services, cloud services, or companies processing data on our behalf.
Attackers steal credentials via phishing, malware, or infostealers and use them to enter as legitimate users, sometimes with elevated privileges.
Without multi-factor authentication, periodic permission reviews, or activity monitoring, an attack can go unnoticed for weeks and result in leaks, destruction, or encryption of large volumes of data.
Artificial intelligence is already used to detect anomalies and suspicious patterns in real time, both in networks and in databases. Machine learning models help identify atypical behavior from users, applications, or services accessing critical information.
However, a new attack surface has emerged: generative AI models and their integrations with applications and databases. Prompt injection attacks manipulate model instructions to extract data or execute unauthorized actions, leading to specific warnings from various cybersecurity agencies.
Even if the context has changed, many classic weaknesses remain entry points in 2025:
Users with simple or reused passwords across different systems, or database access without multi-factor authentication, make life easy for attackers with leaked credentials.
Application accounts and human users with read, write, and admin permissions when they only need to query data. Any compromise of these accounts can lead to deletion, encryption (ransomware), or massive exfiltration.
Modules, services, and default packages installed on the database engine that aren't used, aren't patched, and end up as open doors to known vulnerabilities.
Failing to apply critical patches on time leaves vulnerabilities open to automated attacks on an industrial scale. Unencrypted databases allow unauthorized access to read plain text data.
SQL injection remains one of the most frequent attacks against web apps and APIs accessing databases. Lack of input validation, unparameterized dynamic queries, and missing security testing make it a classic vector that still works.
Building on traditional best practices, we update them with a vision aligned with Zero Trust, cloud, and NIS2 to start 2026 on the right foot:
The goal is to move from "I think it's secure" to "I know exactly where my weaknesses are".
Technology without governance and without a security culture falls short:
At Ambit Iberia, we help companies in regulated and critical sectors protect their most sensitive data, both in on-premise environments and in the cloud. We guide our clients throughout the entire lifecycle:
If you want to review the security of your databases or adapt to new regulatory obligations, we can help you define the right strategy for your organization. Contact us.