Database 250 million records of Microsoft customers was online unprotected

Spread the love

The customer database of Microsoft’s support department was unprotected online and could be viewed for a short time with any web browser, without authentication. The company itself has announced this. It concerns 250 million records, but in many cases private data was not visible.

The database was found online due to a configuration error in the database’s security, Microsoft writes. A change to that configuration took place on December 5 last year, after which security researchers at Comparitech found out on December 29. Microsoft fixed the problem on December 30 and 31, they write.

The database spanned the contacts Microsoft’s support department had with customers between 2005 and the end of 2019. It totaled 250 million records, but in many of those cases, private data had been obscured by the software. In some cases, for example when there were unexpected characters in a field, the information was still readable. Microsoft has said that those affected have been informed. It is unknown how many customers are involved.

According to Comparitech, scammers can misuse the information to improve their impersonation as a Microsoft support representative, a ploy that scammers often use to trick Windows users into money. According to Microsoft, there is no indication that criminals have obtained the database.

You might also like