Microsoft confirmed that business transaction data was accessible without authentication from a misconfigured Internet-facing server, which it secured after SOCRadar reported the issue on September 24, 2022. The company said it found no compromise of customer accounts or systems and notified affected customers directly. SOCRadar said files dated from 2017 to August 2022 could be linked to more than 65,000 entities from 111 countries, a scope Microsoft disputed.

How the exposure occurred

Microsoft attributed the incident to an accidental settings error on an endpoint that is not otherwise used in its environment, rather than to a software flaw. According to SOCRadar, its Cloud Security Module flagged the storage on September 24, 2022 as a misconfigured Azure Blob Storage maintained by Microsoft. SOCRadar later described the repository as belonging to a high-profile cloud provider and said its contents included transaction records tied to planning, implementation and provisioning discussions between Microsoft and prospective customers.

What information was exposed

Microsoft said the accessible material could include names, email addresses, email content, company name, and phone numbers, plus files related to commercial activity with Microsoft or an authorized Microsoft partner. SOCRadar reported that the set included Proof-of-Execution (PoE) and Statement of Work (SoW) documents, user information, product orders/offers, project details, PII (Personally Identifiable Information) data, and documents that may reveal intellectual property.

In its own review of the files, SOCRadar listed customer emails, SOW documents, product offers, POC (Proof of Concept) works, partner ecosystem details, invoices, project details, customer product price list, POE documents, product orders, signed customer documents, internal comments for customers, sales strategies, and customer asset documents. Researcher Kevin Beaumont said on October 20, 2022 that cached material he reviewed independently included emails from US .gov concerning O365 projects and money. SOCRadar warned that anyone who had obtained the bucket contents could reuse them for extortion, blackmailing, social engineering, or resale on the dark web and Telegram channels.

SOCRadar estimated the Microsoft repository alone held 2.4 TB of data, with more than 335,000 emails, 133,000 projects, and 548,000 exposed users identified during its analysis to date.

Scope dispute and BlueBleed lookup

Microsoft said SOCRadar greatly exaggerated the scope of the issue and the numbers, and criticized SOCRadar for gathering the exposed data and offering a dedicated search portal, saying that approach risked customer privacy and security. SOCRadar said no data was downloaded, that only some data was crawled by its engine, that none had been shared, and that crawled copies were deleted from its systems after its commitment to Microsoft, in a statement from VP of Research and CISO Ensar Şeker.

SOCRadar said it directs companies seeking original records to MSRC, with lookup by metadata such as company name, domain name, and email, and said it had to remove its query page following pressure from Microsoft. The company described the portal, named BlueBleed, as letting organizations check whether their information appeared anonymously in open buckets, similar to a B2B version of haveIbeenpwned, while retaining no leaked data itself. In addition to the Microsoft server findings, BlueBleed was presented as covering data observed in five other public storage buckets.

Microsoft told customers in a Microsoft 365 Admin Center alert published on October 4, 2022 that it was unable to provide the specific affected data from the issue. Its support staff reportedly told inquiring customers that no regulator notice beyond customer notifications was needed under GDPR.

Detection and mitigation

Microsoft said its investigation found no indication customer accounts or systems were compromised. Affected customers were notified directly, without public release of per-customer affected records in the admin-center notice.

For organizations that interacted with Microsoft during the 2017 to August 2022 period covered by the files, practical steps based on the data types described are to search mail and file stores for shared PoE, SoW, order, invoice and project documents, watch for follow-on fraud using names, email addresses, company name, phone numbers and email content, and handle any MSRC notice as the authoritative source for what was exposed.

Technical background

This section describes the general class of storage misconfiguration and is not a claim about the specific settings in this incident.

Public cloud object stores commonly distinguish between private containers, where anonymous reads are denied, and containers or blobs marked for anonymous public read. When public read is enabled unintentionally, anyone who can reach the storage endpoint can list or fetch objects without credentials.

Generic illustrative checks administrators use to review exposure include:


# show whether a storage account permits blob public access (generic example)
az storage account show --name <storage-account> --query allowBlobPublicAccess

# list containers and inspect public-access setting (generic example)
az storage container list --account-name <storage-account> --query "[].{name:name, publicAccess:properties.publicAccess}"

General mitigations are to set public access to deny by default, require authorization for every container, audit existing containers for anonymous access, rotate or revoke any credentials or presigned links found in exposed files, and alert on storage-policy changes.