Microsoft
Disclosed Feb 26, 20251 year agoConfirmed
Storm-2139 used stolen customer credentials to hijack Azure OpenAI accounts
Microsoft said the Storm-2139 network used customer credentials scraped from public sources to access accounts on generative AI services including Azure OpenAI, altered their capabilities to bypass safeguards and resold access for creating harmful content such as non-consensual celebrity images. Microsoft named four developers in civil litigation.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Feb 26, 2025 |
| Attack | Credential stuffing |
| Data exposed | Source code, API keys, Credentials and tokens, Internal documents |
| Sector | Tech · US |
| Status | Confirmed |
| Lawsuit or fine | Microsoft civil lawsuit against Storm-2139 defendants (2024-2025) |
Sources
| Source | |
|---|---|
| Thousands of exposed GitHub repositories, now private, can still be accessed through Copilottechcrunch.com · News | News |
| Disrupting a global cybercrime network abusing generative AIblogs.microsoft.com · The organization | The organization |
Notices filed
Other breaches at Microsoft
History of this record
- 2026-09-25 · source_type: press to company · seed source
- 2026-09-25 · source_url: https://techcrunch.com/2025/02/26/thousands-of-exposed-github-repositories-now-private-can-still-be-accessed-through-copilot/ to https://blogs.microsoft.com/on-the-issues/2025/02/27/disrupting-cybercrime-abusing-gen-ai/ · seed source
- 2026-09-25 · status: disclosed to confirmed · seed source
- 2026-09-25 · verified_by: empty to research · seed source
- 2026-09-25 · verified: 0 to 1 · seed source
- 2026-09-25 · lawsuit: empty to Microsoft civil lawsuit against Storm-2139 defendants (2024-2025) · seed source
- 2026-09-25 · attack: ai-model to credential-stuffing · seed source
- 2026-09-25 · summary: Lasso found that once-public GitHub repositories, including ones from large companies and Microsoft, remained retrievable through Microsoft Copilot after being set private because Bing had indexed and cached them. to Microsoft said the Storm-2139 network used customer credentials scraped from public sources to access accounts on generative AI services including Azure OpenAI, altered their capabilities to bypass safeguards and resold access for creating · seed source
- 2026-09-25 · title: Copilot surfaced thousands of GitHub repos after they were made private to Storm-2139 used stolen customer credentials to hijack Azure OpenAI accounts · seed source
- 2026-09-25 · sector: ai to tech · seed source
- 2026-09-25 · data_types: ["source-code","api-keys","credentials"] to ["source-code","api-keys","credentials","internal-docs"] · seed source
- 2026-09-25 · summary: Lasso found that Microsoft Copilot could return content from more than 20,000 GitHub repositories that had been made private or deleted because Bing had indexed and cached them, affecting repositories of major companies including Microsoft. to Lasso found that once-public GitHub repositories, including ones from large companies and Microsoft, remained retrievable through Microsoft Copilot after being set private because Bing had indexed and cached them. · seed source
- 2026-09-25 · title: Copilot surfaced 20,000+ GitHub repos after they were made private to Copilot surfaced thousands of GitHub repos after they were made private · seed source
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research), confirmed by Research. Record counts are as reported. Not legal advice.