News

Microsoft accidentally disclosed database of 250 million customer support users

Microsoft faces yet another data breach that took place in December of the last year. The operating system maker talked about the security breach in a blog post stating that an internal customer support database that was used to store anonymous analytic of users was “accidentally” exposed online without the proper protection.

A local firm known as Security Discover reported the data breach to Microsoft. Bob Diachenko is the researcher who had been working on the security flaw. According to him, the leaked database contained a cluster of five Elastisearch servers, a software that could simplify the search operation. Diachenko told ZDNet in an interview that all 5 of the servers were the image of each other and consisted of the same data.

Microsoft however secured the data on the same day on which Dianchenko reported it to the company.

The 5 servers contained over 240 million entries. The information saved in the entries is IP addresses, email addresses, and support case details. As per Microsoft, the database did not contain any personal information of the users.

Microsoft addressed the situation by saying: “As part of Microsoft’s standard operating procedures, data stored in the support case analytics database is redacted using automated tools to remove personal information.”

Shortly all the impacted users were notified by Microsoft. No malicious use of the exposed data had been observed by the company. The OS maker giant blamed the data leak on misconfigured Azura security rules that had been deployed earlier in December last year.

The company further added that there are certain measures that they are going to take so that the security breach like that would not occur in the future:

    • The established security rules will be audited for internal resources
    • Expansion of the mechanisms that identify misconfiguration of the security rules
    • Once security rule misconfiguration occurs, an additional alert to the service team will be sent
    • Adding extra redaction automation
Sponsored
Naima Rabbie

Leave a Comment
Share
Published by
Naima Rabbie

Recent Posts

China’s Tencent Releases Large Language Model, Opens it For Enterprise Use

Capable of conversing in both Chinese and English, Tencent’s large language model ‘Hunyuan’ is claimed…

8 months ago

Apple Reportedly Spending ‘Million of Dollars Each Day’ for AI Training

Working on multiple AI models, Apple has allocated several teams who are working on artificial…

8 months ago

World’s Largest Wind Turbine Breaks Record For Power Generated In A Single Day-During A Typhoon

The world's largest offshore wind turbine has achieved a milestone by setting a new record…

8 months ago

YouTube Will Let You Play Mini Games Soon

YouTube is stepping into the world of gaming. YouTube has started testing out its gaming…

8 months ago

Pakistani Student Won First Position In Matric Exams of UAE

In a remarkable academic achievement, Abdullah Zaman, a Pakistani student hailing from Attock, has clinched…

8 months ago

‘Flying Bum’ World’s largest Aircraft Is Ready To Launch In 2026 With Hybrid Technology

Flying Bum, the world's largest aircraft is ready to launch in 2026. The Airlander 10…

8 months ago