Microsoft AI researchers expose 38TB confidential data
Microsoft AI researchers accidentally exposed 38 terabytes of confidential and private information on GitHub, raising questions about the company's security practices. Wiz researchers investigating a cloud-hosted data exposure discovered a Microsoft GitHub repository with open-source code for AI image recognition models. The data, some of which had been exposed since July 2020, included backups of two Microsoft employees’ computers, private passwords and passkeys, and more than 30,000 Teams chat messages exchanged by 359 Microsoft employees. Microsoft linked the data exposure to using an excessively permissive Azure Cloud Shared Access Signature (SAS) token . n response, the company expanded GitHub’s secret spanning service, which tracks all public open-source code changes for credentials and other secrets exposed in plaintext. System 🤖 Git H ub 🔗 Operator: Microsoft Developer: Microsoft/Github Country: USA Sector: Technology Purpose: Technology: Computer vision Issue: Security
- Date it happened
- 2023-10-01
- Organisation involved
- Microsoft
- Product, system or model
- Github
This incident was imported from AIAAIC and is used under CC BY-SA 4.0. Our additions to it — the structured fields, the translation, the checks against other reports — are published under the same licence.
This is a record of what was reported, not a finding that anyone broke the law. If it names your organisation and you believe it is wrong, the corrections process is free and open to everyone.