- Blog >
- Data and Research >
- The Map of Exposed Databases Is a Map of Cheap Hosting
The Map of Exposed Databases Is a Map of Cheap Hosting
We examined 1,654 internet-facing databases, each holding at least one million records, spread across 81 countries. The country ranking that gets published every year as a risk map turns out to be measuring something else. In Germany, 52.5% of exposed databases sit with a single low-cost hosting provider. In France, 48.9% sit with another. Exposure clusters around cheap infrastructure, not around borders.
Key Takeaways
- 1,654 internet-facing databases, each holding at least one million records, across 81 countries. Every figure below comes from index metadata. We never connected to any of them.
- Germany: 52.5% sit with a single provider. Hetzner rents virtual machines for a few euros a month. It did not lose any data.
- France: 48.9% sit with a single provider. OVH is Hetzner's French counterpart, and the same applies.
- The United States is the control group: 36% across its top three. Where managed cloud platforms dominate a national market, the same exposure spreads thin instead of concentrating.
- No single provider exceeds 10% of the global sample. Exposure is concentrated within national markets and diffuse globally, which is what you would expect if the driver is local pricing.
- Hosting location isn’t data subject location. A database in Germany may hold records about people who have never been there, operated by a company registered elsewhere, on hardware rented for the price of a coffee.
Finding 1: The Ranking Everyone Publishes Measures the Wrong Thing
The top five countries hold 58.6% of everything in the sample. Read on its own, that chart invites an obvious conclusion: some countries are careless with data. The conclusion doesn’t survive one additional question. Who owns the hardware?

Finding 2: Germany Doesn’t Have a Data Protection Problem. Germany Has Hetzner
Hetzner is a German company that rents virtual machines for a few euros a month. OVH is its French counterpart. Neither of them lost any data. They sold compute to customers in dozens of countries, and some of those customers stood up a database on the public internet with authentication switched off.
So Germany doesn’t have a data protection problem in this sample. Germany has Hetzner. France doesn’t have a data protection problem either. France has OVH.

Finding 3: The United States Is the Control Group
Widen the question from the single largest provider to the top three in each country, and the pattern reverses. Germany's top three account for 74% of its exposed databases. France's for 73%. China's for 66%.
The United States, which holds the second-largest count in the entire sample, comes in at 36%, spread across DigitalOcean, Microsoft, and Google.
That contrast is the actual finding, and it is more interesting than the ranking. Where a national market is dominated by cheap unmanaged hosting, exposure concentrates onto a handful of providers. Where it is dominated by managed cloud platforms, the same exposure spreads thin.

Finding 4: The Operating Model Predicts the Outcome
None of this is about negligent hosts. It is about who performs the configuration step.
An unmanaged virtual machine arrives as an empty operating system. The customer installs the database, the customer decides what address it binds to, and the customer configures the firewall. When an instance ends up bound to 0.0.0.0 with no authentication, that was a tenant decision, not a landlord one.
A managed database service inverts the default. The platform provisions the instance inside a private network, and opening it to the public internet is a deliberate act with a confirmation attached. The exposure rate falls because failure now requires effort rather than merely omission.
Every large provider sells both models. What differs between countries is which model dominates the market, and that is mostly a question of price. Germany and France host an unusually large share of Europe's cheapest unmanaged capacity. The exposure follows the operating model, not the flag on the data centre.
The Global Picture
The ten largest hosting providers account for 43.0% of the whole sample, and no single provider exceeds 10% of it. Exposure is concentrated within national markets and diffuse globally, which is exactly what you would expect if the driver is local pricing rather than any global property of the providers themselves.

Summary
The country ranking that gets published every year as a risk map turns out to be measuring hosting markets.
We examined 1,654 internet-facing databases, each holding at least one million records, spread across 81 countries. In Germany, 52.5% sit with a single low-cost hosting provider. In France, 48.9% sit with another. Neither provider leaked anything.
Exposure clusters around cheap infrastructure, not around borders. The United States demonstrates the inverse: a large exposed population spread across managed cloud platforms, with its top three providers accounting for only 36%.
Hosting location tells you where the electricity is billed. It tells you very little about whose records are at stake, and nothing at all about who is responsible for them.
If you want to know where your data is likely to be exposed, the country ranking is the wrong place to look. The right question is who configured the thing, and under which defaults.
Methodology
The sample is drawn from a public index of internet-exposed services, compiled by continuous scanning of the IPv4 address space. We filtered it to database services reporting at least one million records, which left 1,654 instances across 81 countries.
Country and network ownership come from the index's own geolocation and network attribution. Provider names were normalised by hand, so that entries resolving to the same company under different network names are counted once rather than fragmented across several rows.
We made no connection to any of these systems at any point. Every figure in this piece is derived from index metadata. We did not query a database, read a record, or verify that any individual instance is still reachable, and we are not publishing any host address, network address, or organisation identifier that would let a reader locate one.

Gintarė is a cybersecurity writer at Mysterium VPN, where she explores online privacy, VPN technology, and the latest digital threats in editorial pieces. With hands-on experience researching and writing about data protection and digital freedom, Gintarė makes complex security topics accessible and actionable.
