Observed Signal · Jan 24, 2020 · Security Incident · Source: OnlineMarketing.de · Impact: 4/5 · Sentiment: Negative
Microsoft data leak: 250M user records exposed online
Microsoft disclosed a significant security incident in which data from approximately 250 million Microsoft customers was exposed on the internet for 26 days in December 2019, from December 5 through December 31. The exposed records reportedly included IP addresses, email addresses, and support information. The Microsoft Security Response Center attributed the leak to a misconfigured support database. In its press statement, Microsoft apologized and said it was taking action to prevent recurrence. The company noted that the affected data has since been secured. The incident followed an earlier report in January about Skype conversations being processed with limited privacy protections. The event highlights ongoing privacy and security risks related to data configurations in large organizations and the importance of proper access controls and data governance.
Massive data exposure involving 250 million users; high impact on privacy and security within the AdTech/MarTech ecosystem.
Track Microsoft Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- Approx. 250 million Microsoft customer records were exposed online in 2019.
- Exposure lasted 26 days, from December 5 to December 31, 2019.
- Exposed data included IP addresses, email addresses, and support information.
- Microsoft Security Response Center attributed the leak to a misconfigured support database.
- Microsoft stated the data has since been secured and apologized for the incident; the event followed an earlier January privacy controversy around Skype conversations.
Connected Companies & Entities
1 Entity mappedRelated Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
Microsoft Bug Exposed Confidential Emails to Copilot AI
Microsoft confirmed a software bug allowed its Microsoft 365 Copilot Chat feature to read and summarize customers' confidential draft and sent emails despite data loss prevention (DLP) policies intended to block such ingestion. The flaw — trackable by admins as CW1226324 and first reported by Bleeping Computer — reportedly persisted since January. Microsoft began rolling out a fix in early February but has not disclosed how many customers were affected. The issue prompted at least one institutional response: the European Parliament’s IT department blocked built-in AI features on lawmakers' work devices over confidentiality concerns.
Klaviyo leak exposed some sign-up passwords to advertisers
Security research by Melurna found that a misconfigured sign-up web form on Klaviyo’s site allowed new-customer sign-up information — including email addresses, passwords, company name, website and phone number — to be shared with third-party trackers and advertisers. The misconfiguration was present between at least February 2024 and November 2025, researchers told TechCrunch. Affected third parties reportedly included Facebook, Google, HubSpot, Microsoft/LinkedIn and X. Klaviyo said it fixed the issue and told TechCrunch the number of known affected individuals was fewer than 200 based on active logs; the company would not disclose how far back logs go or publicly share the customer notification. The findings were shared with TechCrunch ahead of a Def Con talk by the researchers.
Meta Data Leak: Tracking Tool Exposed Personal Data
Meta faces a security incident after internal tracking software—introduced in April as the "Model Capability Initiative" to capture mouse movements, clicks and keystrokes for AI training—apparently exposed employee data company‑wide. Over 1,600 employees had previously petitioned against the tool on privacy grounds. Reporting based on an internal security notice indicates information from 45,000 tables was accessible, including full prompts and transcriptions, private conversations, and personnel and performance data. Meta told Wired it is investigating, has disabled the data-collection program pending that probe, and a company CTO acknowledged implementation fell short of privacy-review standards. The incident has deepened internal morale issues following recent layoffs and reassignments.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
