Security News > 2020 > January > Microsoft Error Exposed 250 Million Elasticsearch Records

Microsoft Error Exposed 250 Million Elasticsearch Records
2020-01-23 10:03

Microsoft accidentally internet-exposed for three weeks 250 million customer support records stored in five misconfigured Elasticsearch databases.

Microsoft says the investigation had not uncovered signs of malicious use, and it noted that most of the personal data that had been exposed was redacted.

Roger Grimes, who was formerly a principal security architect at Microsoft and now is with the security firm KnowBe4, says the exposed data included no personally identifiable information, and said it would have been of limited use to hackers.

Microsoft says the "Vast majority" of the records were redacted, as it uses tools to automatically remove personal information.

The company didn't immediately respond to a query from Information Security Media Group asking what percentage of the exposed records may have included unredacted information.


News URL

https://www.inforisktoday.com/microsoft-error-exposed-250-million-elasticsearch-records-a-13639

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Microsoft 725 810 4726 4731 3648 13915
Elasticsearch 8 0 14 1 0 15