Skip to content

Microsoft

10 breachesTechmicrosoft.com

Company profile
BreachAffected
Hijacked Microsoft GitHub repos pushed password stealers to AI coding tool usersJun 83 months agoSupply chainUnverifiedUnknown
Microsoft 365 Copilot Chat bug processed confidential-labeled emails for weeksFeb 187 months agoAI or modelUnverifiedUnknown
Storm-2139 used stolen customer credentials to hijack Azure OpenAI accountsFeb 26, 20251 year agoCredential stuffingUnknown
Russian state hackers access Microsoft senior leadership email accountsJan 19, 20242 years agoHackingUnknown
AI research team's overly permissive SAS token exposed 38TB of internal dataSep 18, 20233 years agoExposed dataUnverifiedUnknown
China-based Storm-0558 forges tokens with stolen Microsoft key to read government emailJul 11, 20233 years agoHackingUnknown
Misconfigured Microsoft storage exposes prospective customer business dataOct 19, 20223 years agoExposed dataUnverifiedUnknown
Lapsus$ compromises a Microsoft account and leaks Bing and Cortana source codeMar 22, 20224 years agoHackingUnknown
Hafnium exploits Exchange Server zero-days to breach on-premises mail serversMar 2, 20215 years agoHackingUnknown
SolarWinds attackers view Microsoft source code repositoriesDec 31, 20205 years agoSupply chainUnknown
About

Every breach here links to its sources and official notices. Across fru.dev: lawsuits, incidents and outages, the company profile.

  • 2026-09-25 · Microsoft, 2025-02-26 · source_type: company
  • 2026-09-25 · Microsoft, 2025-02-26 · source_url: https://blogs.microsoft.com/on-the-issues/2025/02/27/disrupting-cybercrime-abusing-gen-ai/
  • 2026-09-25 · Microsoft, 2025-02-26 · status: confirmed
  • 2026-09-25 · Microsoft, 2025-02-26 · verified_by: research
  • 2026-09-25 · Microsoft, 2025-02-26 · verified: 1
  • 2026-09-25 · Microsoft, 2025-02-26 · lawsuit: Microsoft civil lawsuit against Storm-2139 defendants (2024-2025)
  • 2026-09-25 · Microsoft, 2025-02-26 · attack: credential-stuffing
  • 2026-09-25 · Microsoft, 2025-02-26 · summary: Microsoft said the Storm-2139 network used customer credentials scraped from public sources to access accounts on generative AI services including Azure OpenAI, altered their capabilities to bypass safeguards and resold access for creating
  • 2026-09-25 · Microsoft, 2025-02-26 · title: Storm-2139 used stolen customer credentials to hijack Azure OpenAI accounts
  • 2026-09-25 · Microsoft, 2023-09-18 · added
  • 2026-09-25 · Microsoft, 2025-02-26 · sector: tech
  • 2026-09-25 · Microsoft, 2025-02-26 · data_types: ["source-code","api-keys","credentials","internal-docs"]
  • 2026-09-25 · Microsoft, 2025-02-26 · summary: Lasso found that once-public GitHub repositories, including ones from large companies and Microsoft, remained retrievable through Microsoft Copilot after being set private because Bing had indexed and cached them.
  • 2026-09-25 · Microsoft, 2025-02-26 · title: Copilot surfaced thousands of GitHub repos after they were made private
  • 2026-09-25 · Microsoft, 2026-02-18 · added
  • 2026-09-25 · Microsoft, 2026-06-08 · added
  • 2026-09-25 · Microsoft, 2020-12-31 · added
  • 2026-09-25 · Microsoft, 2021-03-02 · added
  • 2026-09-25 · Microsoft, 2022-03-22 · added
  • 2026-09-25 · Microsoft, 2022-10-19 · added
  • 2026-09-25 · Microsoft, 2023-07-11 · added
  • 2026-09-25 · Microsoft, 2024-01-19 · attack: hacking
  • 2026-09-25 · Microsoft, 2024-01-19 · data_types: ["emails","messages","internal-docs","source-code"]
  • 2026-09-25 · Microsoft, 2024-01-19 · discovered: 2024-01-12
  • 2026-09-25 · Microsoft, 2024-01-19 · summary: Microsoft detected on January 12, 2024 that the Russia-linked group Midnight Blizzard had accessed and exfiltrated data from a small percentage of corporate email accounts, including senior leadership, since late November 2023. In a March 2
  • 2026-09-25 · Microsoft, 2024-01-19 · title: Russian state hackers access Microsoft senior leadership email accounts
  • 2026-09-25 · Microsoft, 2025-02-26 · added
  • 2026-09-25 · Microsoft, 2024-01-19 · added

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.