Cyber Security

Microsoft Data Leak – 250 Million Microsoft Customer Service Support Records Exposed Online

Microsoft exposed a Customer Support Database that contains logs of conversations between Microsoft support agents and customers all over the world.

Nearly 250 million records leaked and the leaked account info ranges 14-year period between 2005 to December 2019.

All the exposed data can be accessible by anyone by just having a web browser, no username or password is required.

Five Elasticsearch Servers Uncovered

The Elasticsearch servers are uncovered by Comparitech security researcher Bob Diachenko, “each of which contained an identical set of the 250 million records.”

Diachenko reached to Microsoft and the exposed data was secured by Microsoft within 24. It is unsure that if any third parties gained access to the database at the time.

The following are the details exposed: Customer email addresses, IP addresses, Locations, Descriptions of CSS claims and cases, Microsoft support agent emails, Case numbers, resolutions, and remarks and Internal notes marked as “confidential”.

The exposed data can be utilized by Tech support scammers to contact users pose to be from Microsft support.

Microsoft Report

Microsoft also released an investigation report states that leak occurs due to “a misconfiguration of an internal customer support database used for Microsoft support case analytics.”

The company also confirms that exposure was limited as the “majority of records were cleared of personal information by our standard practices.”

“We want to sincerely apologize and reassure our customers that we are taking it seriously and working diligently to learn and take action to prevent any future reoccurrence,” Microsoft said.

Also Read

Wawa Hacked – Thousands of Customers Credit and Debit Card Numbers Exposed

WeLeakInfo.com Domain Seized by Law enforcement Agencies for Selling Access to Breached Data

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago