Millions of sensitive data records exposed online due to settings fault with this top Microsoft tool

Data leak
(Image credit: Shutterstock)

  • Researchers from AppOmni found a misconfiguration bug in sites built with Microsoft Power Pages
  • As a result, data on millions of people was leaking on the web
  • UK NHS among affected firms, with other urged to investigate immediately

Businesses in both the private and public sector have been leaking personally identifiable information (PII) on millions of people due to a fault with a Microsoft website builder platform.

Experts from AppOmni revealed the leak stems from misconfigurations in Microsoft’s Power Pages, a low-code platform within the Microsoft Power Platform suite that allows users to build websites without needing to be expert coders.

However, due to misconfigured access controls - namely excessive permissions granted to the Anonymous role - many websites were leaking “significant amounts of data”. That information included full names, email addresses, phone numbers, and home addresses.

NHS among those affected

Power Pages is especially geared toward business users and developers who need to build sites that integrate with business data from sources like Microsoft Dataverse, and apparently has more than 250 million monthly users.

“During my research, I’ve uncovered several million records of sensitive data being exposed to the public internet from authorized testing alone,” the researcher said, suggesting that the leak is probably even bigger (since this was found from “authorized testing alone”). The primary nature of this data are internal organization files and sensitive PII belonging to both internal organization users and other users registered on the website.

Among the leaksters was the NHS - UK’s National Health Service - which allegedly leaked sensitive information belonging to more than 1.1 million employees. The healthcare giant has since plugged the hole. The researchers did not want to name any other organizations leaking the data, possibly because the holes have not yet been plugged.

Misconfigured databases are one of the main causes of data leaks. Over the years, there were many instances of organizations keeping large archives of sensitive customer files without even a weak password, let alone a strong one.

You might also like

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
The best free firewall
Microsoft fixes Power Pages security flaw, tells users to be on their guard
Cartoon Phishing
One of the largest data leaks ever sees info on 1.5 billion people leaked online
healthcare
Over a million clinical records exposed in data breach
Security padlock and circuit board to protect data
A major US TV broadcaster leaked over a million sensitive files online
Data leak
Popular online bill paying site leaks data of thousands of users
healthcare
Software bug meant NHS information was potentially “vulnerable to hackers”
Latest in Security
Isometric demonstrating multi-factor authentication using a mobile device.
NCSC gets influencers to sing the praises of 2FA
Sam Altman and OpenAI
OpenAI is upping its bug bounty rewards as security worries rise
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Dangerous new CoffeeLoader malware executes on your GPU to get past security tools
China
Notorious Chinese hackers FamousSparrow allegedly target US financial firms
A digital representation of a lock
NYU website defaced as hacker leaks info on a million students
NHS
NHS IT supplier hit with major fine following ransomware attack
Latest in News
Nintendo Switch 2 Joy-Con up-close from app store
Nintendo's new app gave us another look at the Switch 2, and there's something different with the Joy-Con
cheap Nintendo Switch game deals sales
Nintendo didn't anticipate that Mario Kart 8 Deluxe was 'going to be the juggernaut' for the Nintendo Switch when it was ported to the console, according to former employees
Three angles of the Apple MacBook Air 15-inch M4 laptop above a desk
Apple MacBook Air 15-inch (M4) review roundup – should you buy Apple's new lightweight laptop?
Witchbrook
Witchbrook, the life-sim I've been waiting years for, finally has a release window and it's sooner than you think
Amazon Echo Smart Speaker
Amazon is experimenting with renaming Echo speakers to Alexa speakers, and it's about time
Shigeru Miyamoto presents Nintendo Today app
Nintendo Today smartphone app is out now on iOS and Android devices – and here's what it does