SECURITY ALERT: Microsoft Accidentally Exposed 250 Million Customer Support Records
#1
Exclamation 
Quote:
[Image: heimdal-logo.svg]

What happened and how to avoid falling prey to phishing attacks and Microsoft support scams.

On January 22, 2020, Microsoft reported a security breach that involved one of its customer databases. Between December 5 and December 31, 2019, a change made to the database’s network security group contained misconfigured security rules that allowed the exposure of data.

Microsoft did not specify how many records were compromised, however, according to Comparitech, 250 million Microsoft customer service and support records ended up being visible on the web.

The databases were discovered by Bob Diachenko, a security researcher, who notified Microsoft immediately. Within 24 hours, all servers were secured.

No malicious parties are known to have accessed the data during the time it was exposed.

What kind of data was exposed?

According to Diachenko, most of the personally identifiable information, such as email aliases, contract numbers, and payment information was redacted. However, many records, like customer email addresses, IP addresses, locations, descriptions of CSS claims and cases, Microsoft support agent emails, case numbers, or Internal notes marked as “confidential” contained plain text data.

In the blog post, Microsoft acknowledged that some data may have remained unredacted under certain conditions. For example, if an email address was written in a non-standard format (name “XYZ @contoso com” vs “XYZ@contoso.com”), the data may have been visible.

Microsoft’s response and action

After the incident, Microsoft took immediate action, apologized to its customers, and began notifying them.

Here are the measures they took to prevent future similar events:

* Auditing the established network security rules for internal resources.
* Expanding the scope of the mechanisms that detect security rule misconfigurations.
* Adding additional alerting to service teams when security rule misconfigurations are detected.
* Implementing additional redaction automation.

How to protect yourself from potential future scams

If you’re a Microsoft customer, you may become a target of scammers trying to impersonate Microsoft’s official staff. Thus, make sure you don’t fall for these scams and read the advice I’ve included below on how you can stay safe.

Do not engage with tech support scammers pretending to work for Microsoft

Surely, Microsoft tech support scams are not new. Even one of Heimdal’s employees received a fake IT support phone call a while ago but recognized it was a scam right away. You can read the full story here and even listen to the phone call recording if you are interested.

Of course, the main piece of advice, in this case, would be not to provide any information about yourself or allow the scammer to remotely access your computer.

Do not open phishing emails pretending to be from Microsoft

Now that the Microsoft data breach incident has been made public, it will be a great time for malicious actors to start sending email phishing campaigns. They may try trick you into entering your Microsoft credentials so you can “reset” them afterward. In the past, we spotted a Microsoft phishing campaign that targeted Office365 users, with pages masquerading as official Microsoft and OneDrive pages.

In short, do not open these emails or click on the malicious links and you’ll be safe. And if you’d like to add an extra layer of safety in your organization, give our DNS filtering solution, Thor Foresight Enterprise, a try.

If you want to learn more about phishing (and spear-phishing, in particular) you may want to go through our complete guide. At the same time, here you can find out all you need to know about how social engineering tactics work.

Stay safe!
...
Continue Reading
[-] The following 1 user says Thank You to harlan4096 for this post:
  • ismail
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
ESET 19.1.12.0
Changes in 19.1.12...harlan4096 — 14:49
Vivaldi 7.9 Build 3970.47
Vivaldi 7.9 Build ...harlan4096 — 07:31
Microsoft Defender Antivirus security in...
Stable channel upd...harlan4096 — 07:25
Microsoft Defender Antivirus security in...
Stable channel upd...harlan4096 — 07:25
Google Chrome 146.0.7680.177/178
Google Chrome 146....harlan4096 — 07:22

[-]
Birthdays
Today's Birthdays
avatar (44)lamSouse
Upcoming Birthdays
avatar (45)wapedDow
avatar (49)oapedDow
avatar (42)Sanchowogy
avatar (46)MeighGoask
avatar (47)creatralGuelm
avatar (38)procnipsut
avatar (44)accenwibly
avatar (41)ahyvily
avatar (38)urumahiz
avatar (44)techlignub
avatar (43)Stevenmam
avatar (50)onlinbah
avatar (50)fuspeukChark
avatar (44)werriewWaiNg
avatar (38)Freemanleo
avatar (48)cticigges
avatar (50)ecoFit
avatar (44)soccejeS
avatar (43)cdoubapKit
avatar (38)lystraPonia
avatar (31)smith8395john
avatar (51)steakelask
avatar (45)Termoplenka
avatar (43)bycoPaist
avatar (49)pieloKat
avatar (43)ilyagNeexy
avatar (51)donitascene
avatar (51)burntLaw
avatar (41)MrDoorsskibheeds
avatar (51)Toligo
avatar (46)Rodneykak
avatar (49)tradeSmode
avatar (39)vemedProkbior
avatar (38)RobertUtelt
avatar (46)JamesZic
avatar (43)Sanfordbup
avatar (38)Der.Reisende
avatar (41)alapesihy
avatar (36)Kiran78

[-]
Online Staff
There are no staff members currently online.

>