Skip to content

Microsoft

Disclosed Feb 26, 20251 year agoConfirmed

Official notice

Storm-2139 used stolen customer credentials to hijack Azure OpenAI accounts

Microsoft said the Storm-2139 network used customer credentials scraped from public sources to access accounts on generative AI services including Azure OpenAI, altered their capabilities to bypass safeguards and resold access for creating harmful content such as non-consensual celebrity images. Microsoft named four developers in civil litigation.

What is known

People affectedNot stated in the sources we have
DisclosedFeb 26, 2025
AttackCredential stuffing
Data exposedSource code, API keys, Credentials and tokens, Internal documents
SectorTech · US
StatusConfirmed
Lawsuit or fineMicrosoft civil lawsuit against Storm-2139 defendants (2024-2025)

Sources

Notices filed

WhereFiledPeople
ResearchtotalFeb 26, 2025
ResearchtotalFeb 26, 2025
ResearchtotalFeb 27, 2025

Other breaches at Microsoft

BreachAffected
Hijacked Microsoft GitHub repos pushed password stealers to AI coding tool usersJun 83 months agoSupply chainUnverifiedUnknown
Microsoft 365 Copilot Chat bug processed confidential-labeled emails for weeksFeb 187 months agoAI or modelUnverifiedUnknown
Russian state hackers access Microsoft senior leadership email accountsJan 19, 20242 years agoHackingUnknown
AI research team's overly permissive SAS token exposed 38TB of internal dataSep 18, 20233 years agoExposed dataUnverifiedUnknown
China-based Storm-0558 forges tokens with stolen Microsoft key to read government emailJul 11, 20233 years agoHackingUnknown
Misconfigured Microsoft storage exposes prospective customer business dataOct 19, 20223 years agoExposed dataUnverifiedUnknown
Lapsus$ compromises a Microsoft account and leaks Bing and Cortana source codeMar 22, 20224 years agoHackingUnknown
Hafnium exploits Exchange Server zero-days to breach on-premises mail serversMar 2, 20215 years agoHackingUnknown
SolarWinds attackers view Microsoft source code repositoriesDec 31, 20205 years agoSupply chainUnknown
History of this record
  • 2026-09-25 · source_type: press to company · seed source
  • 2026-09-25 · source_url: https://techcrunch.com/2025/02/26/thousands-of-exposed-github-repositories-now-private-can-still-be-accessed-through-copilot/ to https://blogs.microsoft.com/on-the-issues/2025/02/27/disrupting-cybercrime-abusing-gen-ai/ · seed source
  • 2026-09-25 · status: disclosed to confirmed · seed source
  • 2026-09-25 · verified_by: empty to research · seed source
  • 2026-09-25 · verified: 0 to 1 · seed source
  • 2026-09-25 · lawsuit: empty to Microsoft civil lawsuit against Storm-2139 defendants (2024-2025) · seed source
  • 2026-09-25 · attack: ai-model to credential-stuffing · seed source
  • 2026-09-25 · summary: Lasso found that once-public GitHub repositories, including ones from large companies and Microsoft, remained retrievable through Microsoft Copilot after being set private because Bing had indexed and cached them. to Microsoft said the Storm-2139 network used customer credentials scraped from public sources to access accounts on generative AI services including Azure OpenAI, altered their capabilities to bypass safeguards and resold access for creating · seed source
  • 2026-09-25 · title: Copilot surfaced thousands of GitHub repos after they were made private to Storm-2139 used stolen customer credentials to hijack Azure OpenAI accounts · seed source
  • 2026-09-25 · sector: ai to tech · seed source
  • 2026-09-25 · data_types: ["source-code","api-keys","credentials"] to ["source-code","api-keys","credentials","internal-docs"] · seed source
  • 2026-09-25 · summary: Lasso found that Microsoft Copilot could return content from more than 20,000 GitHub repositories that had been made private or deleted because Bing had indexed and cached them, affecting repositories of major companies including Microsoft. to Lasso found that once-public GitHub repositories, including ones from large companies and Microsoft, remained retrievable through Microsoft Copilot after being set private because Bing had indexed and cached them. · seed source
  • 2026-09-25 · title: Copilot surfaced 20,000+ GitHub repos after they were made private to Copilot surfaced thousands of GitHub repos after they were made private · seed source
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research), confirmed by Research. Record counts are as reported. Not legal advice.

Everything about Microsoft

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.