• Tuesday, Mar 28, 2023
  • Last Update : 10:24 am

Millions of Microsoft-stored data records mistakenly exposed

  • Published at 12:38 pm August 24th, 2021
Microsoft
File photo: A Microsoft logo is seen in Los Angeles, California, US June 14, 2016 Reuters

The data, including names, addresses, financial information and Covid-19 vaccination statuses

Some 38 million records stored on a Microsoft service, including private information, were mistakenly left exposed this year, security firm UpGuard said on Monday.

The data, including names, addresses, financial information and Covid-19 vaccination statuses, was made vulnerable -- but not compromised -- before the problem was resolved, according to the digital security company's investigation.

Among the 47 affected organizations were American Airlines, Ford, JB Hunt and public agencies such as the Maryland Department of Health and New York City's public transit system.

They all used a Microsoft product called Power Apps, which allows for the creation of websites and mobile apps to interact with the public.

The service's default software configuration setting meant the data of the affected organizations was left without protection up until June 2021, according to UpGuard.

"As a result of this research project, Microsoft has since made changes to Power Apps portals," the report said.

Microsoft said it had let clients know when potential security risks were uncovered so that they could fix the problems themselves. 

"We take security and privacy seriously, and we encourage our customers to use best practices when configuring products in ways that best meet their privacy needs," a spokesperson said. 

But UpGuard said it would have been better to change the way the software works at the source, and based on how customers use it, rather than "to label systemic loss of data confidentiality an end user misconfiguration, allowing the problem to persist."

50
Facebook 50
blogger sharing button blogger
buffer sharing button buffer
diaspora sharing button diaspora
digg sharing button digg
douban sharing button douban
email sharing button email
evernote sharing button evernote
flipboard sharing button flipboard
pocket sharing button getpocket
github sharing button github
gmail sharing button gmail
googlebookmarks sharing button googlebookmarks
hackernews sharing button hackernews
instapaper sharing button instapaper
line sharing button line
linkedin sharing button linkedin
livejournal sharing button livejournal
mailru sharing button mailru
medium sharing button medium
meneame sharing button meneame
messenger sharing button messenger
odnoklassniki sharing button odnoklassniki
pinterest sharing button pinterest
print sharing button print
qzone sharing button qzone
reddit sharing button reddit
refind sharing button refind
renren sharing button renren
skype sharing button skype
snapchat sharing button snapchat
surfingbird sharing button surfingbird
telegram sharing button telegram
tumblr sharing button tumblr
twitter sharing button twitter
vk sharing button vk
wechat sharing button wechat
weibo sharing button weibo
whatsapp sharing button whatsapp
wordpress sharing button wordpress
xing sharing button xing
yahoomail sharing button yahoomail