Microsoft has announced a data breach after some of its customers' sensitive information was exposed by a misconfigured Microsoft server that was accessible over the Internet. The company secured the server in question after being notified of the data leak on September 24 , 2022. Microsoft was notified of the security incident by researchers at SOCRadar .

“This misconfiguration resulted in access unauthenticated,” the company revealed.
See also: Medibank hack: Hackers threaten to leak Australians' data
“Our investigation found no indication that customer accounts or systems were compromised. We have notified affected customers directly“.
According to the company's statement, the exposed information includes names, email addresses, email, company name and phone numbers, as well as records associated with business activities between customers and Microsoft or an authorized Microsoft partner.
The company explained that the customer data leak was caused by “an unintentional misconfiguration on an endpoint not used in the Microsoft ecosystem.” No security vulnerability is responsible for this leak.
Microsoft: Leaked data linked to 65,000 entities?
Microsoft did not provide further details about the data breach. However, SOCRadar researchers revealed in a report that the data was stored in misconfigured Azure Blob Storage. SOCRadar claims it was able to link this sensitive information to more than 65,000 entities, across 111 countries. The data was stored in files dating from 2017 to August 2022.
“On September 24, 2022, SOCRadar’s Cloud Security Module detected a misconfigured Azure Blob Storage maintained by Microsoft containing sensitive data from a high-profile cloud provider,” SOCRadar reported.
See also: Hackers target online casinos in Asia for espionage

The company added that the leaked data “includes Proof-of-Execution (PoE) and Statement of Work (SoW) documents, user information, product orders/quotes, project details, personal information, data and documents that may reveal intellectual property.”
For its part, Microsoft said it believes SOCRadar “greatly exaggerated the scope of this issue” and “the numbers”Additionally, the company said SOCRadar’s decision to collect the data and make it searchable using a dedicated search portal “privacy or security customer.”
Searching for leaked data
SOCRadar's data breach search portal is called BlueBleed and allows companies to find out if their sensitive information was exposed in the leaked data
In addition to what was found inside the misconfigured Microsoft server, BlueBleed also allows searching of data collected from five other public storage buckets.
On Microsoft's server alone, there was 2.4TB of data, according to SOCRadar. This data contained sensitive information, with more than 335,000 emails, 133,000 projects, and 548,000 exposed users.
See also: Verizon: Notifies customers of account breach
SOCRadar researchers' analysis showed that these files contain customer emails, SOW documents, product quotes, POC (Proof of Concept) projects, POE documents, partner ecosystem details, invoices, customer product price lists, project details, product orders, signed customer documents, internal customer, sales strategies, and customer asset documents.
Anyone who has access to this information can use it for various scams and extortion. They can also sell it to other cybercriminals.
Source: www.bleepingcomputer.com
