Microsoft Data Breach: 250 Million Customer Service Records Exposed Online

The leaked records contained logs of conversations spanned a 14-year period from 2005 to December 2019.

Advertisement
By Indo-Asian News Service | Updated: 23 January 2020 18:06 IST
Highlights
  • Nearly 250 million customer service records were exposed
  • Misconfiguration of an internal customer support database was the reason
  • Data was left accessible to anyone with a Web browser

Microsoft engineers remediated the configuration on December 31, 2019

Microsoft has admitted it exposed nearly 250 million customer service records owing to "misconfiguration of an internal customer support database" used for tracking support cases that included logs of conversations between Microsoft support agents and customers from all over the world. All of the Microsoft customers' data was left accessible to anyone with a Web browser, with no password or other authentication needed, it was reported first by the Comparitech security research team led by Bob Diachenko.

"While the investigation found no malicious use, and although most customers did not have personally identifiable information exposed, we want to be transparent about this incident with all customers and reassure them that we are taking it very seriously and hold ourselves accountable," Ann Johnson, Corporate Vice President, Cybersecurity Solutions Group at Microsoft said in a statement late Wednesday.

Microsoft's investigation determined that a change made to the database's network security group on December 5, 2019 contained misconfigured security rules that enabled exposure of the data.

Advertisement

According to the company, its engineers remediated the configuration on December 31, 2019 to restrict the database and prevent unauthorised access.

Advertisement

"This issue was specific to an internal database used for support case analytics and does not represent an exposure of our commercial cloud services," said the tech giant in a blog post.

The records contained logs of conversations spanned a 14-year period from 2005 to December 2019.

Advertisement

"We want to sincerely apologise and reassure our customers that we are taking it seriously and working diligently to learn and take action to prevent any future reoccurrence," said Microsoft.

The company thanked Diachenko for helping it fix the misconfiguration.

Advertisement

"I immediately reported this to Microsoft and within 24 hours all servers were secured," Diachenko said. "I applaud the MS support team for responsiveness and quick turnaround on this despite New Year's Eve."

Diachenko explained that most of the personally identifiable information "emails, contract numbers, and payment information" was redacted.

However, many records contained plain text data, including but not limited to customer email addresses, IP addresses, locations, Microsoft support agent emails, case numbers, resolutions, and remarks and internal notes marked as "confidential".

According to the researchers, with detailed logs and case information in hand, scammers stand a better chance of succeeding against their targets.

If scammers obtained the data before it was secured, they could exploit it by impersonating a real Microsoft employee and referring to a real case number.

"Microsoft customers and Windows users should be on the lookout for such scams via phone and email. Remember that Microsoft never proactively reaches out to users to solve their tech problems "users must approach Microsoft for help first," said the Comparitech team.

This is not Microsoft's first data security incident.

In 2013, hackers broke into the company's secret database for tracking bugs in its software.

Between January and March 2019, hackers compromised the account of a Microsoft support agent. The company said there was a possibility that the hacker accessed the contents of some Outlook users' accounts.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: Microsoft
Advertisement

Related Stories

Popular Mobile Brands
  1. Realme GT 8, Realme GT 8 Pro With Ricoh GR Optics Launched: See Price
  2. OnePlus 15 Battery Capacity, Charging Speed Teased Days Ahead of Launch
  3. OnePlus 15 India Launch Teased; Key Features Revealed Ahead of Launch
  4. iQOO 15 vs iPhone 17 Pro Max: Features, Price and Specifications Compared
  5. Redmi K90 Pro Max Key Features Revealed Ahead of Launch on October 23
  6. BSNL Samman Plan For Senior Citizens Announced at This Price
  7. Diwali Blackout: How the AWS Outage Crippled Major Apps Across the World
  8. iQOO 15 Launched With Snapdragon 8 Elite Gen 5, 50-Megapixel Cameras
  9. iOS 26.1 Beta 4 Lets You Tone Down Apple's Liquid Glass Design
  10. Poco F8 Ultra Listing on NBTC Certification Site Hints at Imminent Launch
  1. iQOO Neo 11 Confirmed to Come With 2K Display and 7,500mAh Battery; Colour Options Tipped
  2. MacBook Pro 14-inch (2025) and iPad Pro With M5 Chip Now Available in India: Prices and Other Details Here
  3. Samsung Galaxy XR Headset Launched With Hand Tracking, Snapdragon XR2+ Gen 2 SoC: Price, Specifications
  4. Samsung Galaxy XR Headset Launching Today: Know Price, Features, and Specifications
  5. Smartwatch Breakthrough Brings GPS Accuracy Down to a Few Centimetres
  6. SpaceX Launches 10,000th Starlink Satellite, Sets New Annual Record
  7. Scientists Discover New Seismic Clue to Predict Mount Etna Eruptions
  8. NASA and ESA Trace Mysterious Lunar Flashes to Meteors and Gas Leaks
  9. Valsala Club Is Streaming Now: Know All About the Malayali Comedy-Drama Movie
  10. Ganoshotru OTT Release: Know When and Where to Watch the Bengali Crime-Thriller Online
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.