Skip to content
OnMSFT.com
  • Home
  • About
  • Contact
  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Edge
  • Teams
  • Gaming
Menu
  • Home
  • About
  • Contact
  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Edge
  • Teams
  • Gaming
  1. Home
  2. News
  3. Microsoft mistakenly leaks 30K+ internal employee messages, passwords, secret keys

Microsoft mistakenly leaks 30K+ internal employee messages, passwords, secret keys

OnMSFT Staff OnMSFT Staff
September 18, 2023
2 min read

Microsoft AI researchers accidentally made a lot of private information, like passwords and secret messages, available to anyone who knew where to look on GitHub. This happened because they used a special link that gave people too much access to their data, according to data shared with TechCrunch by cloud security firm Wiz.

During its ongoing research, Wiz discovered that cloud-hosted data was accidentally exposed. In particular, Wiz identified a Microsoft GitHub repository linked to the company’s AI research division. The repository contained open-source code and AI models that could be used for image recognition, with users instructed to download the models from an Azure Storage URL.

The accidentally shared data included 38 terabytes of critical information. It contained personal backups from two Microsoft employees, passwords, secret keys, and messages from Microsoft employees.

The data was exposed due to a misconfigured shared access signature (SAS) token. Azure uses SAS tokens, a mechanism that allows users to create shareable links granting access to an Azure Storage account’s data.

The data has been exposed through a misconfigured URL since 2020. Wiz discovered that the URL allowed “full control” instead of “read-only” permissions. Anyone who knows where to look could delete, replace, or insert malicious content into the data.

Microsoft stated that no customer data was exposed, and no other internal services were at risk due to this issue.

This incident underscores the importance of robust security practices when handling sensitive data, especially in the context of AI research and open-source projects. It also highlights the need for ongoing monitoring and safeguards to prevent accidental data exposure.

 

Related

Share this article:
Previous Article Panos Panay is leaving Microsoft Next Article PC Game Pass titles may be coming to Xbox Cloud Gaming very soon

Related Articles

Chrome’s Organizer feature may sync Gemini and AI conversations across devices

March 14, 2026

After Chrome, Edge tests launching the browser automatically when you sign into Windows

March 13, 2026
Latest iPhone Fold rumors reveal display crease details, hole-punch cameras, iOS multitasking layout, 12GB RAM, and storage options for Apple’s first foldable iPhone.

iPhone Fold Latest Rumors: Display, Cameras, RAM and Price Details Revealed

March 13, 2026

Leave a Comment Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • Chrome’s Organizer feature may sync Gemini and AI conversations across devices
  • After Chrome, Edge tests launching the browser automatically when you sign into Windows
  • iPhone Fold Latest Rumors: Display, Cameras, RAM and Price Details Revealed
  • Samsung fears first mobile operating loss due to memory price surge
  • Elon Musk’s X to Change Verification in Europe Following EU Fine

Recent Comments

No comments to show.
OnMSFT.com

OnMSFT.com covers Microsoft news, reviews, and how-to guides. Formerly known as WinBeta, we have been your source for Microsoft news since 1998.

Categories

  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Gaming
  • Edge
  • Teams

Recent Posts

  • Chrome’s Organizer feature may sync Gemini and AI conversations across devices
  • After Chrome, Edge tests launching the browser automatically when you sign into Windows
  • iPhone Fold Latest Rumors: Display, Cameras, RAM and Price Details Revealed
  • Samsung fears first mobile operating loss due to memory price surge
  • Elon Musk’s X to Change Verification in Europe Following EU Fine

Quick Links

  • About OnMSFT.com
  • Contact OnMSFT
  • Join Our Team
  • Privacy Policy
© 2010–2026 OnMSFT.com LLC. All rights reserved.
About OnMSFT.comContact OnMSFTPrivacy Policy