{"id":11923,"date":"2026-07-06T11:49:15","date_gmt":"2026-07-06T09:49:15","guid":{"rendered":"https:\/\/mybox.com\/help\/?post_type=manual_kb&#038;p=11923"},"modified":"2026-07-06T11:49:22","modified_gmt":"2026-07-06T09:49:22","slug":"why-downloaded-backups-should-be-stored-securely","status":"publish","type":"manual_kb","link":"https:\/\/mybox.com\/help\/en\/knowledgebase\/why-downloaded-backups-should-be-stored-securely\/","title":{"rendered":"Why downloaded backups should be stored securely"},"content":{"rendered":"\n<div class=\"translation-block translation-block-merged\">\n<p class=\"wp-block-paragraph\">A downloaded backup is a copy of website, database, email, or hosting data saved outside the hosting environment. Backups are useful for recovery, but they can also contain sensitive information that should not be exposed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This article explains why downloaded backups need to be stored securely, what risks they can create, and what to check before sharing, uploading, or keeping backup files long term.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_86 ez-toc-wrap-left counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/why-downloaded-backups-should-be-stored-securely\/#What_a_backup_may_contain\" >What a backup may contain<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/why-downloaded-backups-should-be-stored-securely\/#Why_backups_are_sensitive\" >Why backups are sensitive<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/why-downloaded-backups-should-be-stored-securely\/#Public_backup_files_are_a_security_risk\" >Public backup files are a security risk<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/why-downloaded-backups-should-be-stored-securely\/#Backups_can_expose_passwords_and_secrets\" >Backups can expose passwords and secrets<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/why-downloaded-backups-should-be-stored-securely\/#Downloaded_backups_can_become_outdated\" >Downloaded backups can become outdated<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/why-downloaded-backups-should-be-stored-securely\/#Where_backups_should_be_stored\" >Where backups should be stored<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/why-downloaded-backups-should-be-stored-securely\/#How_to_store_backups_more_safely\" >How to store backups more safely<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/why-downloaded-backups-should-be-stored-securely\/#Be_careful_when_sharing_backups\" >Be careful when sharing backups<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/why-downloaded-backups-should-be-stored-securely\/#Backup_archives_and_search_engines\" >Backup archives and search engines<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/why-downloaded-backups-should-be-stored-securely\/#What_to_do_if_a_backup_was_public\" >What to do if a backup was public<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-11\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/why-downloaded-backups-should-be-stored-securely\/#Practical_meaning_for_users\" >Practical meaning for users<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-12\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/why-downloaded-backups-should-be-stored-securely\/#Summary\" >Summary<\/a><\/li><\/ul><\/nav><\/div>\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_a_backup_may_contain\"><\/span>What a backup may contain<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<\/div>\n\n<div id=\"mybox-374254569\" class=\"mybox-content mybox-entity-placement\"><div class=\"early-access-banner-inpost\">\r\n  <div class=\"banner-left-inpost\">\r\n    <div class=\"icon-box-inpost\">\r\n      <img decoding=\"async\" src=\"https:\/\/mybox.com\/help\/wp-content\/uploads\/2026\/02\/square-info-icon.svg\" alt=\"Info\">\r\n    <\/div>\r\n    <div class=\"text-box-inpost\">\r\n      <span class=\"label-inpost\"><span class=\"translation-block translation-block-banner-text\">Early access<\/span><\/span>\r\n      <h4><span class=\"translation-block translation-block-banner-text\">Still need help?<\/span><\/h4>\r\n      <p><span class=\"translation-block translation-block-banner-text\">Contact our customer service team.<\/span><\/p>\r\n    <\/div>\r\n  <\/div>\r\n\r\n  <div class=\"banner-right-inpost\">\r\n    <a href=\"https:\/\/panel.mybox.com\/helpdesk2\/v\/list\/\" class=\"banner-button-inpost\"><span class=\"translation-block translation-block-banner-text\">Message us<\/span><\/a>\r\n  <\/div>\r\n<\/div><\/div>\n\n<div class=\"translation-block translation-block-merged\"><p class=\"wp-block-paragraph\">A hosting backup can include more than website files.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Depending on how it was created, a backup may contain:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>website files<\/li>\n\n\n\n<li>databases<\/li>\n\n\n\n<li>uploaded media<\/li>\n\n\n\n<li>configuration files<\/li>\n\n\n\n<li>email data<\/li>\n\n\n\n<li>usernames<\/li>\n\n\n\n<li>hashed passwords<\/li>\n\n\n\n<li>API keys<\/li>\n\n\n\n<li>SMTP credentials<\/li>\n\n\n\n<li>database credentials<\/li>\n\n\n\n<li>customer or user information<\/li>\n\n\n\n<li>order data<\/li>\n\n\n\n<li>form submissions<\/li>\n\n\n\n<li>logs<\/li>\n\n\n\n<li>private documents<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Even if the website itself is public, the backup may contain data that was never meant to be visible online.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Why_backups_are_sensitive\"><\/span>Why backups are sensitive<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A backup can give someone a detailed copy of your website or hosting account.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If the backup includes configuration files, it may reveal database access details, application secrets, or integration keys. If it includes a database, it may contain user accounts, email addresses, orders, messages, or other private records.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Because of this, a backup should be treated as sensitive data. It should not be stored casually, shared through public links, or left inside folders that can be accessed from the browser.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Public_backup_files_are_a_security_risk\"><\/span>Public backup files are a security risk<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A common mistake is downloading a backup and then uploading it back into a public website folder.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If a backup archive is placed inside a public web directory, it may become downloadable from a URL.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For example, files such as these should not be publicly accessible:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>backup.zip\nwebsite-backup.tar.gz\ndatabase.sql\npublic_html-backup.zip\nold-site.zip\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">If someone can download the backup, they may be able to inspect the website code, database content, credentials, and private data inside it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Backups_can_expose_passwords_and_secrets\"><\/span>Backups can expose passwords and secrets<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Some backups include files that contain credentials or application secrets.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Examples include:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>wp-config.php\n.env\nconfiguration.php\nconfig.php\ndatabase.sql\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">These files may contain database names, database users, passwords, salts, API keys, SMTP settings, or other values used by the application.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If a backup containing these files is exposed, changing only the website password may not be enough. Any exposed secret should be replaced.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Downloaded_backups_can_become_outdated\"><\/span>Downloaded backups can become outdated<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A backup is a snapshot from a specific moment.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Keeping old backups can be useful, but they may also contain outdated software, old credentials, or data that should no longer be retained. If old backups are stored without review, they can increase security and privacy risk over time.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Backups should be kept only as long as they are useful and should be deleted securely when no longer needed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Where_backups_should_be_stored\"><\/span>Where backups should be stored<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Downloaded backups should be stored in a location that is not publicly accessible.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Suitable storage options may include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>an encrypted local drive<\/li>\n\n\n\n<li>a secure external drive<\/li>\n\n\n\n<li>a private cloud storage account<\/li>\n\n\n\n<li>a backup service with access control<\/li>\n\n\n\n<li>a protected internal storage location<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The important point is that access should be limited to people who actually need it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_to_store_backups_more_safely\"><\/span>How to store backups more safely<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Use a careful process when handling downloaded backups.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Store backups outside public website folders.<\/li>\n\n\n\n<li>Use strong passwords for storage accounts.<\/li>\n\n\n\n<li>Enable two-factor authentication where available.<\/li>\n\n\n\n<li>Encrypt backup files when possible.<\/li>\n\n\n\n<li>Limit who can access the backup.<\/li>\n\n\n\n<li>Avoid sharing backups through public links.<\/li>\n\n\n\n<li>Remove backups from temporary locations after use.<\/li>\n\n\n\n<li>Keep only the backups you still need.<\/li>\n\n\n\n<li>Delete old backups securely.<\/li>\n\n\n\n<li>Rotate credentials if a backup was exposed.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">These steps reduce the chance that a recovery file becomes a new security problem.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Be_careful_when_sharing_backups\"><\/span>Be careful when sharing backups<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Sometimes a backup needs to be shared with a developer, agency, or support team.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Before sharing it, confirm what data is included and whether the recipient needs the full backup. In some cases, a specific file, error log, or database table may be enough.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If a full backup must be shared, use a private transfer method and remove access after the work is complete. Avoid public download links that remain active indefinitely.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Backup_archives_and_search_engines\"><\/span>Backup archives and search engines<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If a backup file is placed in a public folder, search engines or automated scanners may discover it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Even if the link is not published on a page, the file may still be found through predictable filenames, directory listings, logs, or automated scans.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A file should not be considered private only because the URL is not widely known.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_to_do_if_a_backup_was_public\"><\/span>What to do if a backup was public<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If a backup file was publicly accessible, treat it as a possible security incident.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Recommended actions include:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Remove the public backup file immediately.<\/li>\n\n\n\n<li>Check whether similar backup files are also public.<\/li>\n\n\n\n<li>Review access logs if available.<\/li>\n\n\n\n<li>Change database passwords included in the backup.<\/li>\n\n\n\n<li>Rotate API keys, SMTP passwords, and application secrets.<\/li>\n\n\n\n<li>Review website users and administrator accounts.<\/li>\n\n\n\n<li>Check whether the database contains sensitive user data.<\/li>\n\n\n\n<li>Monitor the website for suspicious activity.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">The correct response depends on what the backup contained and how long it may have been accessible.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Practical_meaning_for_users\"><\/span>Practical meaning for users<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Backups are important because they help restore a website after mistakes, failed updates, malware, or data loss. The same backup can also create risk if it is stored in the wrong place.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A downloaded backup should be handled like a private copy of your hosting account. Store it securely, limit access, and remove it when it is no longer needed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Summary\"><\/span>Summary<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Downloaded backups should be stored securely because they may contain website files, databases, credentials, user data, email data, and private configuration details.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A backup should never be left in a public website folder or shared through an unrestricted link. Secure storage, limited access, encryption, and careful cleanup help keep backups useful without creating unnecessary risk.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n<\/div>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"template":"","format":"standard","manualknowledgebasecat":[10],"manual_kb_tag":[],"class_list":["post-11923","manual_kb","type-manual_kb","status-publish","format-standard","hentry","manualknowledgebasecat-safety"],"_links":{"self":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/11923","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb"}],"about":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/types\/manual_kb"}],"author":[{"embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/users\/1"}],"version-history":[{"count":1,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/11923\/revisions"}],"predecessor-version":[{"id":11924,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/11923\/revisions\/11924"}],"wp:attachment":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/media?parent=11923"}],"wp:term":[{"taxonomy":"manualknowledgebasecat","embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manualknowledgebasecat?post=11923"},{"taxonomy":"manual_kb_tag","embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb_tag?post=11923"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}