AGL 37.55 Increased By ▲ 0.05 (0.13%)
AIRLINK 218.49 Decreased By ▼ -4.40 (-1.97%)
BOP 10.68 Decreased By ▼ -0.14 (-1.29%)
CNERGY 7.32 Decreased By ▼ -0.24 (-3.17%)
DCL 9.10 Decreased By ▼ -0.32 (-3.4%)
DFML 40.35 Decreased By ▼ -0.61 (-1.49%)
DGKC 102.20 Decreased By ▼ -4.56 (-4.27%)
FCCL 34.40 Decreased By ▼ -2.67 (-7.2%)
FFL 19.50 Increased By ▲ 0.26 (1.35%)
HASCOL 12.82 Decreased By ▼ -0.36 (-2.73%)
HUBC 130.69 Decreased By ▼ -1.95 (-1.47%)
HUMNL 14.42 Decreased By ▼ -0.31 (-2.1%)
KEL 5.27 Decreased By ▼ -0.13 (-2.41%)
KOSM 7.20 Decreased By ▼ -0.28 (-3.74%)
MLCF 45.45 Decreased By ▼ -2.73 (-5.67%)
NBP 65.79 Decreased By ▼ -0.50 (-0.75%)
OGDC 220.12 Decreased By ▼ -3.14 (-1.41%)
PAEL 44.25 Increased By ▲ 0.75 (1.72%)
PIBTL 9.08 Increased By ▲ 0.01 (0.11%)
PPL 192.28 Decreased By ▼ -5.96 (-3.01%)
PRL 41.60 Decreased By ▼ -0.64 (-1.52%)
PTC 26.69 Decreased By ▼ -0.70 (-2.56%)
SEARL 107.29 Decreased By ▼ -2.79 (-2.53%)
TELE 10.32 Decreased By ▼ -0.20 (-1.9%)
TOMCL 35.86 Decreased By ▼ -0.76 (-2.08%)
TPLP 14.48 Decreased By ▼ -0.47 (-3.14%)
TREET 25.86 Decreased By ▼ -0.67 (-2.53%)
TRG 67.34 Decreased By ▼ -1.51 (-2.19%)
UNITY 33.50 Decreased By ▼ -0.69 (-2.02%)
WTL 1.75 Decreased By ▼ -0.04 (-2.23%)
BR100 12,291 Decreased By -72.5 (-0.59%)
BR30 37,354 Decreased By -863.8 (-2.26%)
KSE100 116,637 Decreased By -482.9 (-0.41%)
KSE30 36,770 Decreased By -166.8 (-0.45%)
Technology

Millions of Microsoft-stored data records mistakenly exposed

  • The data, including names, addresses, financial information and Covid-19 vaccination statuses
Published August 24, 2021

SAN FRANCISCO: Some 38 million records stored on a Microsoft service, including private information, were mistakenly left exposed this year, security firm UpGuard said Monday.

The data, including names, addresses, financial information and Covid-19 vaccination statuses, was made vulnerable -- but not compromised -- before the problem was resolved, according to the digital security company's investigation.

Among the 47 affected organizations were American Airlines, Ford, JB Hunt and public agencies such as the Maryland Department of Health and New York City's public transit system.

They all used a Microsoft product called Power Apps, which allows for the creation of websites and mobile apps to interact with the public.

The service's default software configuration setting meant the data of the affected organisations was left without protection up until June 2021, according to UpGuard.

"As a result of this research project, Microsoft has since made changes to Power Apps portals," the report said.

Microsoft said it had let clients know when potential security risks were uncovered so that they could fix the problems themselves.

"We take security and privacy seriously, and we encourage our customers to use best practices when configuring products in ways that best meet their privacy needs," a spokesperson said.

But UpGuard said it would have been better to change the way the software works at the source, and based on how customers use it, rather than "to label systemic loss of data confidentiality an end user misconfiguration, allowing the problem to persist."

Comments

Comments are closed.