Assume that I do not enable encryption at rest for my POSTGRES database, and the database is installed in a VM which has bitlocker encryption.
If a hacker copies the database files, can they read the data? How can the copied database files be misused by hackers if the database is not encrypted at rest?