• Skip to main content
  • Our Services
  • Industries
  • Resources
  • About
  • Contact
Valeo Logo - WhiteValeo Logo
888-290-0588Client Portal
Valeo Logo - WhiteValeo Logo
  • Our Services
    • Managed IT Services
      • 24/7 Helpdesk
      • 24/7 Network Monitoring
      • Backup & Disaster Recovery
      • IT Consulting
      • Technology Business Reviews
      • Vendor Management
      • Procurement
      • Server Virtualization
      • Wi-Fi Management
    • Cybersecurity
      • Security Operations Center
      • Antivirus and Malware
      • Network Security
      • Vulnerability Testing
      • Penetration Testing
      • Risk Assessment
    • Cloud Solutions
      • Hosted Private Cloud
      • Hybrid Cloud
      • Public Cloud Vendors
      • Office 365 Migration
      • Hosted VoIP Solutions
    • Compliance
      • NIST 800-171/CMMC
      • HIPAA/HITECH
      • PCI DSS
      • FINRA
      • SOX
      • SOC 2
      • FISMA
      • FERPA
      • CCPA
  • Industries
    • Accounting
    • Construction & Development
    • Education
    • Finance
    • Government Contractors
    • Healthcare
    • Hospitality
    • Insurance
    • Legal
    • Manufacturing
    • Municipalities
    • Native American & Tribal Organizations
    • Non-Profit Organizations
    • Real Estate
    • Retail
  • Resources
    • Managed Services Guide for C Suite Executives
    • Blog
    • Resource Center
  • About
    • Success Stories
    • In the News
    • Partners
    • Careers
  • Contact
    • Locations
      • Arizona
      • California
      • Florida
      • Iowa
      • Oregon
888-290-0588Client Portal

Microsoft Breach Exposes 250 Million Customer Service Records

person on laptop

Microsoft has alerted users to a massive data breach that exposed approximately 250 million customer service support (CSS) records. The breach was discovered December 29 by a Comparitech security research team led by Bob Diachenko. Microsoft disclosed the security lapse on January 22, blaming it on a “misconfiguration of an internal customer support database used for Microsoft support case analytics.”

The exposed data included logs of conversations between Microsoft support personnel and customers from across the globe, spanning a 14-year period from 2005 to 2019. The data was visible to “anyone with a web browser” and no password or authentication were required to view the data. After being notified of the breach by Comparitech, Microsoft took action to secure the data.

Microsoft said its investigation found “no malicious use” of user data occurred and that customers did not have their personally identifiable information (PII) exposed. However, Comparitech noted that some information, such as email and IP addresses, was stored in plain text. Someone accessing the logs could have used the information they contained to impersonate the company’s support staff in a phishing scheme.

Comparitech researcher Paul Bischoff wrote in a posting Wednesday that the customer data trove contained everything a cybercriminal would need to mount a convincing and large-scale fraud effort.

“The data could be valuable to tech support scammers, in particular,” he said. “Tech support scams entail a scammer contacting users and pretending to be a Microsoft support representative. These types of scams are quite prevalent, and even when scammers don’t have any personal information about their targets, they often impersonate Microsoft staff. Microsoft Windows is, after all, the most popular operating system in the world.”

Recent Posts

  • Valeo Networks Acquires Next I.T., Further Expanding National MSSP Reach in the Midwest Region
  • Valeo Networks Named to ChannelE2E Top 100 Vertical Market MSPs: 2022 Edition
  • 8 Best Practices for Backup and Disaster Recovery Planning
  • Valeo Networks Recognized on CRN’s 2022 MSP 500 List in the Security 100 Category
  • Valeo Networks Named to ChannelE2E’s Top 250 Public Cloud MSPs List for 2021

Categories

  • Backups
  • Cloud/Virtualization
  • Compliance
  • Cybersecurity
  • General
  • IT Storage
  • Managed IT Services
  • News
  • Security

Please complete the form to access this resource. Once you fill out the form, you will have unlimited access to all other content in the Resource Center.

Valeo Logo - White
About

With cutting-edge technology and quality customer service, you’ll find everything you need to help your company soar with Valeo Networks.

Explore Valeo
  • Our Services
  • Industries
  • Resources
  • About
  • Contact
Contact

888-290-0588

info@valeonetworks.com

1006 Pathfinder Way
Rockledge, FL 32955

Copyright © 2022 Valeo Networks. All Rights Reserved. Privacy Policy.