A cluster of five internal customer service and support databases tracking historical user interactions spanning 14 years was inadvertently exposed to the web without authentication due to a misconfigured network security rule.