Microsoft
Disclosed Sep 18, 20233 years agoUnverified
AI research team's overly permissive SAS token exposed 38TB of internal data
A Microsoft AI research GitHub repo shared an Azure SAS token that granted access to a whole storage account, exposing 38TB including workstation backups of 359 employees, secrets, private keys, passwords and over 30,000 Teams messages. Wiz reported it in June 2023 and the token was revoked two days later.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Sep 18, 2023 |
| Discovered | Jun 22, 2023 |
| Attack | Exposed data |
| Data exposed | Credentials and tokens, Internal documents, Messages, Passwords |
| Sector | Tech · US |
| Status | Unverified: not yet confirmed by an official notice, a filing or the organization |
Sources
| Source | |
|---|---|
| Microsoft AI researchers accidentally exposed terabytes of internal sensitive datatechcrunch.com · News | News |
| 38TB of data accidentally exposed by Microsoft AI researcherswiz.io · News | News |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Sep 18, 2023 |
Other breaches at Microsoft
History of this record
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.