ANY.RUN research identified a large-scale data leak event triggered by a false positive in Microsoft Defender XDR. The security platform incorrectly flagged benign files as malicious, leading to their automatic submission to ANY.RUN’s public sandbox for analysis. As a result, over 1,700 sensitive documents were uploaded and indexed publicly.
The leak, which involved corporate data from hundreds of companies, has raised alarm bells about the risks of misclassification in threat detection systems and the unintended consequences of user behavior in response to such errors.
The incident began when Microsoft Defender XDR, a widely used advanced threat protection platform, mistakenly flagged legitimate Adobe Acrobat Cloud links specifically URLs starting with acrobat[.]adobe[.]com/id/urn:aaid:sc:—as malicious.
According to a ANYRUN report shared with Cyber Security News , this error triggered a sudden influx of Adobe Acrobat Cloud links being uploaded to their sandbox for analysis.
Many of these uploads were initiated by users on ANYRUN’s free plan, which defaults to public sharing mode, inadvertently exposing sensitive corporate documents to the wider internet.
ANYRUN’s investigation revealed that the false positive led free-plan users to upload more than 1,700 Adobe files containing confidential data, affecting hundreds of organizations.

“Earlier today, we noticed an unusual surge in uploads containing Adobe Acrobat Cloud links. Our team traced it back to a false positive from Microsoft Defender XDR, which mistakenly flagged the following legitimate URL as malicious: acrobat[.]adobe[.]com/id/urn:aaid:sc:” ANY.RUN shared the report with Cyber Security News.
The exposed documents included a wide range of sensitive information, raising concerns about potential data breaches and the misuse of proprietary corporate information.
In response, ANYRUN swiftly moved to mitigate the damage by converting all related analyses to private mode, preventing further public exposure. However, the company noted that some users continued to upload confidential documents publicly, exacerbating the issue.
“We saw a sudden inflow of Adobe Acrobat Cloud links being uploaded to ANYRUN’s sandbox a couple of hours ago.” “To stop leaks, we’re making all these analyses private, but users continue to share confidential documents publicly. Always use a commercial license for work-related tasks to ensure privacy and compliance.”
As noted in a web report by PUPUWEB on April 24, 2025, false positives can erode trust in detection systems and lead to significant security risks if not addressed promptly.
In this case, the misclassification by Microsoft Defender XDR prompted users to take actions that inadvertently exposed sensitive data, underscoring the need for accurate threat detection to prevent such cascading effects.
The report also advised users encountering false positives in Microsoft Defender XDR to submit them to Microsoft for analysis and resolution, a step that could help prevent similar incidents in the future.
The ANYRUN data leak also ties into ongoing discussions about the evolving landscape of cyber threats, particularly in cloud environments.
Just a day earlier, on April 23, 2025, cybersecurity expert Florian Roth (@cyb3rops) posted on X about how attackers are increasingly bypassing traditional endpoints to target cloud platforms like Microsoft 365, Google Workspace, and AWS.
Roth noted that cloud environments often suffer from limited logging, lack of robust detection mechanisms, and blind spots that make them attractive targets for attackers.
The ANYRUN incident serves as a stark reminder of how errors in cloud-related security tools can amplify these vulnerabilities, leading to unintended consequences like widespread data exposure.
The incident has sparked renewed calls for organizations to adopt more secure practices when handling sensitive data, particularly in cloud-based environments.
Additionally, the event underscores the need for cybersecurity tools to balance sensitivity with accuracy to avoid false positives that can lead to significant collateral damage.
As the cybersecurity landscape continues to evolve, incidents like this serve as a critical reminder of the importance of vigilance, accurate threat detection, and robust user education.
Are you from SOC and DFIR Teams? – Analyse Malware Incidents & get live Access with ANY.RUN -> Start Now for Free.
