Skip to content
OnMSFT.com
  • Home
  • About
  • Contact
  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Edge
  • Teams
  • Gaming
Menu
  • Home
  • About
  • Contact
  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Edge
  • Teams
  • Gaming
  1. Home
  2. News
  3. Former Microsoft security expert claims company has hosted malware in OneDrive for nearly a decade – onmsft.com

Former Microsoft security expert claims company has hosted malware in OneDrive for nearly a decade – onmsft.com

Kareem Anderson Kareem Anderson
October 20, 2021
3 min read

Since the early 2000’s Microsoft has made it a company-wide endeavor to emphasize security in many of its products, unfortunately, it seems company can’t keep up with volume of threats that exist today.

A former Microsoft Senior Threat Intelligence Analyst, Kevin Baumont took to Twitter last week to vent his frustrations over what he has seen as OneDrive malware abuse.

In an opening tweet to an informative thread, Baumont encourages Microsoft, who employs eight thousand security personnel and received trillions of signals to do a better job at preventing OneDrive from being a host to Conti ransomware.

Microsoft cannot advertise themselves as the security leader with 8000 security employees and trillions of signals if they cannot prevent their own Office365 platform being directly used to launch Conti ransomware.

OneDrive abuse has been going on for years.

Fix it. https://t.co/GFpbi8KcXB

— Kevin Beaumont (@GossiTheDog) October 15, 2021

Baumont also shares receipts of report and action times from the OneDrive team that reach close to a month for a response from Microsoft when contacted about a potential threat.

Even more of an indictment than the molasses-like response times is the claim that Microsoft manages to profit off its delayed reactions.

Amusingly MS consume your API and use it to block things on your lists in their security products (I was on the team doing it), but nobody wants to clean up the network. So get screwed, non-E5.

— Kevin Beaumont (@GossiTheDog) October 15, 2021

As a former Senior Threat Intelligence Analyst, Baumont also gives some insight into competitors approaches and the outlook is just as dire elsewhere. According to a 3rd party analyst firm Abuse.ch, while Microsoft ranks in the top three platforms hosting malware, Google and Discord top the list as well as Slack and Pastebin rounding out the top five. The issue of malware isn’t isolated to Microsoft, but Baumont’s criticisms shine a brighter light on the issues the company continuously struggle with.

Furthermore, Microsoft acknowledges Baumont’s observations and agrees that it will need to investigate further improvements to better respond to and prevent the hosting of malware within its products. Microsoft told OnMSFT:

“Abuse of cloud storage is an industry-wide issue and we’re constantly working to reduce the use of Microsoft services to cause harm. We are investigating further improvements to prevent and rapidly respond to the types of abuse listed in this report. We continue to encourage customers to practice good computing habits online, including exercising caution when clicking on links to web pages, opening unknown files, or accepting file transfers, and we also encourage customers to report abuse using this form.”

However, as an industry-wide issue with cloud storage, the company will need to also work with others to come up with more permanent solutions.

Baumont’s Twitter exposé of Microsoft’s OneDrive malware abuses does conclude on a positive note with updates showing Microsoft addressing some of his concerns.

We have good news — after years OneDrive is finally hosting no malware listed on @abuse_ch, and for the first time in history Microsoft have fallen off the top ten malware hosters.

All the Bazaloader, BazaISO and Qakbot TR payloads are gone.

Keep it up MS. Customers are safer. pic.twitter.com/Z126Md3ncO

— Kevin Beaumont (@GossiTheDog) October 19, 2021

Malware in all its forms is an increasing problem for everyone, Microsoft and OneDrive included, but it’s good to see both the problems get some exposure and some progress being made.

Share This Post:

Share this article:
Tags:
Malware Microsoft OneDrive
Previous Article Microsoft misses its growth target for Xbox Game Pass subscriptions Next Article Windows 11 Insider build 22483 is now available for Dev Channel Insiders – onmsft.com

Related Articles

Chrome and Gemini icons representing Gemini Live voice assistant integration in Chrome

Chrome tests Gemini Live voice assistant in a floating overlay panel

March 14, 2026

Chrome’s Organizer feature may sync Gemini and AI conversations across devices

March 14, 2026

After Chrome, Edge tests launching the browser automatically when you sign into Windows

March 13, 2026

Leave a Comment Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • Chrome tests Gemini Live voice assistant in a floating overlay panel
  • Chrome’s Organizer feature may sync Gemini and AI conversations across devices
  • After Chrome, Edge tests launching the browser automatically when you sign into Windows
  • iPhone Fold Latest Rumors: Display, Cameras, RAM and Price Details Revealed
  • Samsung fears first mobile operating loss due to memory price surge

Recent Comments

No comments to show.
OnMSFT.com

OnMSFT.com covers Microsoft news, reviews, and how-to guides. Formerly known as WinBeta, we have been your source for Microsoft news since 1998.

Categories

  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Gaming
  • Edge
  • Teams

Recent Posts

  • Chrome tests Gemini Live voice assistant in a floating overlay panel
  • Chrome’s Organizer feature may sync Gemini and AI conversations across devices
  • After Chrome, Edge tests launching the browser automatically when you sign into Windows
  • iPhone Fold Latest Rumors: Display, Cameras, RAM and Price Details Revealed
  • Samsung fears first mobile operating loss due to memory price surge

Quick Links

  • About OnMSFT.com
  • Contact OnMSFT
  • Join Our Team
  • Privacy Policy
© 2010–2026 OnMSFT.com LLC. All rights reserved.
About OnMSFT.comContact OnMSFTPrivacy Policy