Original Release Date: 1/27/2020
Microsoft disclosed a security breach affecting five Elasticsearch servers that stored an internal customer support database. The servers contained approximately 250 million entries; however, some personally identifiable information (PII) had been redacted. Exposed data included: customer email addresses, IP addresses, locations, descriptions of CSS claims and cases, Microsoft support agent emails, case numbers, resolutions, remarks, and internal notes marked as “confidential.” This information could be used by threat actors to fabricate future support scams. The database was secured within 24 hours of notification and the resulting investigation determined that the accidental exposure was caused by misconfigured security rules established on December 5, 2019.