Don't miss the latest stories
Advertise Newsletter
Network
  • The Creative Finder
  • The Bazaar
  • Deals
  • Status Is Down
Community
  • Sign up / Log in
  • Discussion Forums
  • Calendar of Events
NEW

Follow

Share this

Microsoft
Cars
COVID-19
Disputes
Technology
Travel
  • Disputes
  • Technology
  • Travel
MENU
  • Advertise with us
  • Submit tip/feedback
  • Work with us
  • Subscribe to newsletter
  • Subscribe to RSS
Advertise here
Advertisement

Microsoft App Leak Exposed 38 Million Records, Including COVID-19 Details

By Alexa Heah, 24 Aug 2021

Subscribe to newsletter
Like us on Facebook

Image via ID 176267769 © Boggy | Dreamstime.com

Turns out, a leaked COVID-19 contact-tracing database in Indiana was part of a broader problem connected to Microsoft’s Power Apps tool.

According to a report by UpGuard, organizations that used Power Apps were left exposed to a default setting that made datasets findable on search engines, or accessible by anyone who knew the direct web address.

In total, 47 organizations were notified of the leak, with 38 million records exposed. More worryingly, these records include names, birthdates, addresses, and even social security numbers.

There were government organizations hit by the leak, including the Indiana Department of Health’s database, which extended to 750,000 people. UpGuard had discovered records belonging to the Maryland Department of Health’s COVID-19 testing appointments, New York City Department of Education rosters, and the New York Metropolitan Transit Authority’s (MTA) list of vaccinated employees.

Other files were also attributed to large corporations such as American Airlines, Ford Motor Company, and several of Microsoft’s internal documents.

The leaks had occurred due to the Power Apps’ portal default setting, which creates websites that “give both internal and external users secure access” to data. UpGuard’s Vice President of Cyber Research, Greg Pollock, told StateScoop that the leaks were uncovered on May 24, after an analyst was curious about Microsoft Power Apps’ built-in sites.

Advertisement
Advertisement


After the researcher had found a “significant number” of web addresses where data was left unprotected, the firm checked if it was available for public viewing. If the site’s operator had not fiddled with the default settings, the data would be accessible to anyone with the know-how.

UpGuard said it first reported the discovery to Microsoft on June 24, with an analyst from the latter firm replying the same day. However, despite UpGuard analysts sharing their findings, Microsoft proceeded to close the case on June 29, having “determined that this behavior is considered to be by design.”

After which, UpGuard decided to inform the affected organizations directly. Most of the companies responded, securing the data lists after a few days. Some companies weren’t as easy to reach, with the MTA and the New York City Department of Education taking a long time to reply. Eventually, the data was secured.

Recently, in response to the breach, Microsoft has released a tool to detect if data lists allow anonymous access. Plus, it’s also updated the Power Apps tool so that all data is now set to secure by default.

“This is one of the better outcomes for this process,” said Pollock.



[via StateScoop, cover image via ID 176267769 © Boggy | Dreamstime.com]
Receive interesting stories like this one in your inbox
Advertise here

More related news

Advertise here
Also check out these recent news
Web Design
Link to news page

When Your Website Goes Down, This Is the Page Customers Meet Instead

2027
Link to news page

2027 Already Has A Color Of The Year And It’s Beginning On ‘Grounded’ Territory

IKEA
Link to news page

IKEA & Xbox Press Play On Furniture & Storage Inspired By The Iconic Controller

Fashion
Link to news page

Vogue Presents ‘United Flags of Fashion’ With Top Designers For All 50 States

Coca-Cola
Link to news page

Coca-Cola Pours Fresh Life Into Its Iconic Branding With Worldwide Redesign