
Microsoft recently revealed a data leak that took place last December.
In a blog post published by the company, it said that an internal customer support database, which stores anonymous user analytics, was exposed between December 5 and 31.
The database leak was discovered and reported to Microsoft by Bob Diachenko, a security researcher at Security Discovery.
According to Diachenko, the customer support database that was exposed online consists of a cluster of five Elasticsearch servers , a technology used to simplify search operations . All five servers store the same data .
The researcher also stated that Microsoft resolved the issue immediately, despite the fact that it was New Year's Eve.
The servers contained about 250 million records, including information such as email addresses, IP addresses and support details. Microsoft said most of the files did not contain any personal user information.
However, in cases where users submitted support requests using non-standard formatted data such as (“firstnamelastname@emaildomain com” instead of “firstname_signature@email.com”), they remained in the exposed database.
For these users, the company has begun sending notifications, in which it also informs them that no malicious use of their data has been detected.
According to Microsoft, the database leak was the result of poorly configured Azure, which have now been fixed. As Microsoft stated, now:
- Established network security rules for internal resources are checked.
- The range of mechanisms that detect misleading variations in security rules is being expanded.
- Additional notifications are provided to service teams when incorrect security configuration settings are detected.
- Additional processing automation is implemented.
