Abraham Jewett  |  October 21, 2022

Category: Data Breach

Top Class Actions’s website and social media posts use affiliate links. If you make a purchase using such links, we may receive a commission, but it will not result in any additional charges to you. Please review our Affiliate Link Disclosure for more information.

Microsoft building against a blue sky in Houston, Texas.
(Photo Credit: Riyard Ramnath/Shutterstock)

Microsoft data breach overview: 

  • Who: Microsoft revealed that a misconfigured internet-accessible Microsoft server exposed some of its customers’ sensitive information. 
  • Why: Microsoft said an “unintentional” misconfiguration on an endpoint “not in use” in its ecosystem caused the data breach.
  • Where: Microsoft is used by consumers nationwide. 

Microsoft disclosed to the public yesterday that some sensitive customer information was exposed due to a misconfigured internet-accessible Microsoft server. 

In a blog post, the tech company says it “quickly secured” the endpoint of the misconfigured server after security researchers at Tech Intelligence Firm SOCRadar notified it of the data leak on Sept. 24. 

The misconfiguration led to the “potential for unauthenticated access” to certain business transaction data that corresponds to interactions between Microsoft and its prospective customers, according to the Microsoft data breach blog post. 

The issue was caused by an unintentional misconfiguration on an endpoint that is not in use across the Microsoft ecosystem and was not the result of a security vulnerability,” Microsoft says in the post. 

Microsoft also reassured consumers that it didn’t find any indication that any customer accounts or systems were compromised due to the misconfigured server and that it contacted any affected customers directly. 

Microsoft data breach includes names, email content, among other things

Data exposed in the Microsoft data breach included customer names, email content, company names and phone numbers and email addresses, Microsoft says in the blog post. It “may have included attached files relating to business between a customer and Microsoft or an authorized Microsoft partner,” according to the company. 

Microsoft says that it is “working to improve our processes” to avoid similar types of misconfigurations going forward as well as “performing additional due diligence to investigate and ensure the security of all Microsoft endpoints.” 

Consumers or organizations who did not receive a Message Center communication from Microsoft about the breach are not impacted by the issue, according to the company. 

In June, Microsoft announced that it would be officially retiring its Internet Explorer web browser while redirecting its users to Microsoft Edge. 

Have you had your personal information exposed by the Microsoft data breach? Let us know in the comments! 


Don’t Miss Out!

Check out our list of Class Action Lawsuits and Class Action Settlements you may qualify to join!


Read About More Class Action Lawsuits & Class Action Settlements:

We tell you about cash you can claim EVERY WEEK! Sign up for our free newsletter.

153 thoughts onMicrosoft data breach compromises customers’ sensitive information due to misconfigured server

  1. D says:

    Please add me. I have 2 different Microsoft outlook accounts, as well as Xbox.

  2. Cheryl Barham says:

    Please add me

    1. Jessica W says:

      My Microsoft account has been used to access my sensitive data. Please add me to this data breach.

  3. Wanda A Banner says:

    Add me some one hacked my Microsoft and get fb friend request and these some one looks my ask did hear of new program from government

  4. Stephanie Gonzalez says:

    I had my account overtaken, created fraud, phishing and spoofing. They took access over my amount and security in all my verification approvals. Transferred my days internationally. I would like to be added.

  5. Yvette says:

    Microsoft is not safe! You buy their products and they promise you it works but it don’t pls add me

    1. Thomas Robert Kelly says:

      They are so unprotected and allowed all of our private information out there.

  6. Marcia Rambharan says:

    Add Me please all of my info is on there

  7. Joseph labonte says:

    Add me please

  8. Alejandrino Ramirez says:

    Add me please

  9. Tasia says:

    Add Me

    1. Alejandrino Ramirez says:

      Add me please

Leave a Reply

Your email address will not be published. By submitting your comment and contact information, you agree to receive marketing emails from Top Class Actions regarding this and/or similar lawsuits or settlements, and/or to be contacted by an attorney or law firm to discuss the details of your potential case at no charge to you if you qualify. Required fields are marked *

Please note: Top Class Actions is not a settlement administrator or law firm. Top Class Actions is a legal news source that reports on class action lawsuits, class action settlements, drug injury lawsuits and product liability lawsuits. Top Class Actions does not process claims and we cannot advise you on the status of any class action settlement claim. You must contact the settlement administrator or your attorney for any updates regarding your claim status, claim form or questions about when payments are expected to be mailed out.