Skip to content

Microsoft

Disclosed Sep 18, 20233 years agoUnverified

AI research team's overly permissive SAS token exposed 38TB of internal data

A Microsoft AI research GitHub repo shared an Azure SAS token that granted access to a whole storage account, exposing 38TB including workstation backups of 359 employees, secrets, private keys, passwords and over 30,000 Teams messages. Wiz reported it in June 2023 and the token was revoked two days later.

What is known

People affectedNot stated in the sources we have
DisclosedSep 18, 2023
DiscoveredJun 22, 2023
AttackExposed data
Data exposedCredentials and tokens, Internal documents, Messages, Passwords
SectorTech · US
StatusUnverified: not yet confirmed by an official notice, a filing or the organization

Sources

Notices filed

WhereFiledPeople
ResearchtotalSep 18, 2023

Other breaches at Microsoft

BreachAffected
Hijacked Microsoft GitHub repos pushed password stealers to AI coding tool usersJun 83 months agoSupply chainUnverifiedUnknown
Microsoft 365 Copilot Chat bug processed confidential-labeled emails for weeksFeb 187 months agoAI or modelUnverifiedUnknown
Storm-2139 used stolen customer credentials to hijack Azure OpenAI accountsFeb 26, 20251 year agoCredential stuffingUnknown
Russian state hackers access Microsoft senior leadership email accountsJan 19, 20242 years agoHackingUnknown
China-based Storm-0558 forges tokens with stolen Microsoft key to read government emailJul 11, 20233 years agoHackingUnknown
Misconfigured Microsoft storage exposes prospective customer business dataOct 19, 20223 years agoExposed dataUnverifiedUnknown
Lapsus$ compromises a Microsoft account and leaks Bing and Cortana source codeMar 22, 20224 years agoHackingUnknown
Hafnium exploits Exchange Server zero-days to breach on-premises mail serversMar 2, 20215 years agoHackingUnknown
SolarWinds attackers view Microsoft source code repositoriesDec 31, 20205 years agoSupply chainUnknown
History of this record
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.

Everything about Microsoft

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.