Microsoft has reported a leak of confidential data from its customers. The problem has already been fixed
Microsoft reported a leak of confidential data of some customers. Due to an incorrectly configured company server, the information was freely available for some time. It is not specified how long the server has been vulnerable and whether anyone has gained access to the information stored on it.
The vulnerability was reported by SOCRadar information security specialists on September 24. Now the problem has already been fixed.
According to Microsoft, due to the bug, attackers could gain unauthorized access to data related to its interaction with potential customers regarding the planning, implementation and provision of services. The company reported the problem to customers it may have affected. No signs of compromise of anyone's accounts or systems were found during the investigation.
Among the data that was made publicly available were names, email addresses, email content, company names, phone numbers, and related files. They belonged to more than 65 thousand Microsoft customers from 111 countries and were stored in files dated from 2017 to August 2022.
According to SOCRadar experts, we are talking about 2.4 TB of data with sensitive information, 335 thousand electronic messages, 133 thousand projects and 548 thousand users.
Microsoft said that SOCRadar "greatly exaggerates the scale of the problem" and the number of customers who could potentially be affected by the leak.