Connect with us

E-Business

Microsoft Exposes 250m Customer Records

Published

on

Kindly share this post

Over the New Year, software giant Microsoft exposed nearly 250 million customer service and support (CSS) records on the Web.

This is according to UK-based firm Comparitech, which says the records contained logs of conversations between Microsoft support agents and customers from all over the world, spanning a 14-year period from 2005 to December 2019.

All of the data was left accessible to anyone with a Web browser, with no password or other authentication needed, the firm says.

The Comparitech security research team led by Bob Diachenko uncovered five Elasticsearch servers, each of which contained an apparently identical set of the 250 million records.

Diachenko immediately notified Microsoft upon discovering the exposed data, and Microsoft took swift action to secure it.

Advertisement

“We’re thankful to Bob Diachenko for working closely with us so that we were able to quickly fix this misconfiguration, analyse data and notify customers as appropriate,” says Eric Doerr, general manager of Microsoft.

Timeline of the exposure

Comparitech says in total, the data was exposed for about two days before it alerted Microsoft and the records were secured.

–    28 December 2019: The databases were indexed by search engine BinaryEdge.

–    29 December 2019: Diachenko discovered the databases and immediately notified Microsoft.

Advertisement

–   30 and 31 December 2019: Microsoft secured the servers and data. Diachenko and Microsoft continued the investigation and remediation process.

–   21 January 2020: Microsoft disclosed additional details about the exposure as a result of the investigation.

“I immediately reported this to Microsoft and within 24 hours all servers were secured,” Diachenko says.

“I applaud the Microsoft support team for responsiveness and quick turnaround on this despite [it being] New Year’s Eve. We do not know if any other unauthorised parties accessed the database during that time.”

Diachenko explains that most of the personally identifiable information – e-mail aliases, contract numbers and payment information – was redacted.

Advertisement

However, he points out that many records contained plain text data, including but not limited to customer e-mail addresses, IP addresses, locations, descriptions of CSS claims and cases, Microsoft support agent e-mails, case numbers, resolutions and internal notes marked as “confidential”.

Comparitech notes that even though most personally identifiable information was redacted from the records, the dangers of this exposure should not be underestimated.

The data could be valuable to tech support scammers, in particular, it says.

“Tech support scams entail a scammer contacting users and pretending to be a Microsoft support representative. These types of scams are quite prevalent, and even when scammers don’t have any personal information about their targets, they often impersonate Microsoft staff. Microsoft Windows is, after all, the most popular operating system in the world,” the firm says.

It points out that with detailed logs and case information in hand, scammers stand a better chance of succeeding against their targets.

Advertisement

“If scammers obtained the data before it was secured, they could exploit it by impersonating a real Microsoft employee and referring to a real case number. From there, they could phish for sensitive information or hijack user devices.

“Microsoft customers and Windows users should be on the lookout for such scams via phone and e-mail. Remember that Microsoft never proactively reaches out to users to solve their tech problems – users must approach Microsoft for help first. Microsoft employees will not ask for your password or request that you install remote desktop applications like TeamViewer. These are common tactics among tech scammers,” Comparitech says.

Kindly share this post

Dear Reader, Your support matters. But we believe that technology makes life more exciting and helps improve the lives of people around Nigeria and indeed the world. That is why, we have devoted our energy to independent reportage of technology and finance and how they affect lives. Our incisive and analytical view of how technology news affects the daily life help individuals and organizations make up their minds. Quality journalism costs money. Today, we're asking that you support us to do more. Kindly support our effort to deliver technology and finance journalism to everyone in the world. Donate as little as N1,000. Bank transfers can be made to: UBA Plc 1017156876 Communication Week Media Ltd

E-Business

NDPC Probes UNILAG, Lotus Bank, Hackerbella over Alleged Students’ Data Misuse

Published

on

Kindly share this post

Nigeria Data Protection Commission (NDPC) has commenced a forensic investigation into the University of Lagos (UNILAG), Lotus Bank and Hackerbella Ltd over alleged violations of data protection laws involving students’ personal information.

NDPC Probes UNILAG, Lotus Bank, Hackerbella over Alleged Students’ Data Misuse

The investigation follows public complaints alleging that students’ personal data were used to open bank accounts without a lawful basis.

Dr Vincent Olatunji, national commissioner and chief executive officer of the NDPC, directed the investigation team to conduct a comprehensive assessment of the circumstances surrounding the collection, processing, use and disclosure of the affected students’ personal data.

The investigation will also determine the respective roles and responsibilities of UNILAG, Lotus Bank and Hackerbella in the alleged processing of the data.

According to the Commission, the investigation will assess the data protection compliance obligations of the parties under the Nigeria Data Protection Act, 2023 (NDP Act), as well as potential risks posed to the rights and freedoms of the affected data subjects.

Advertisement

The NDPC said the probe would cover several areas, including Data Protection Impact Assessments (DPIAs), the lawfulness and transparency of credit scoring or profiling activities, and the use of automated decision-making systems.

It will also examine the adequacy of privacy notices, data-sharing arrangements, lawful bases for processing, data minimisation and purpose limitation.

Other areas include data retention policies and the adequacy of technical and organisational measures put in place to safeguard the rights and personal data of affected students.

The Commission reiterated that institutions entrusted with the personal data of students, staff and other members of their communities have a heightened responsibility to ensure that such information is processed lawfully, fairly, transparently and securely.

The NDPC therefore warned educational institutions that are yet to comply with its existing data protection compliance directives to take immediate steps to achieve compliance.

Advertisement

The Commission said it would continue to exercise its regulatory mandate to protect the privacy rights of Nigerians and ensure that organisations processing personal data comply with the provisions of the Nigeria Data Protection Act, 2023.

Kindly share this post
Continue Reading

E-Business

Microsoft to Unveil Next-generation AI Chip in September

Published

on

Kindly share this post

Microsoft is planning to unveil its new Maia 300 AI chip this fall, potentially as soon ​as next month, The Information reported on Monday, citing ‌people with direct knowledge of the plans.

The company introduced its Maia AI chip in November 2023 but has lagged rivals such as Alphabet and ​Amazon in scaling up its in-house chip efforts as ​it seeks to reduce its reliance on Nvidia’s costly ⁠processors.

Google began recognizing revenue from direct sales of its custom ​AI chips, called Tensor Processing Units, in the quarter ended June, ​while Amazon has also seen growing adoption of its processors, including its Trainium chips.

Microsoft has been in talks with chipmaker TSMC to secure manufacturing ​capacity for more than 300,000 units of the chip for ​delivery in 2027, according to the report. It is also looking to significantly ramp up ‌production ⁠and persuade major cloud customers such as Anthropic to adopt the chip.

Microsoft ultimately ​aims to ⁠secure capacity for more than 1 million Maia 300 chips, though component supplies and ongoing capacity ​negotiations with TSMC could constrain its plans, according ​to the ⁠report.

Advertisement

It unveiled its second-generation Maia 200 in January, built by TSMC using 3-nanometer technology.

Microsoft packed the chip with a significant amount of ⁠SRAM, ​a type of memory that can provide ​speed advantages for AI systems handling large numbers of user requests.

 

Kindly share this post
Continue Reading

E-Business

X Replaces Revenue Sharing wit New Creator Rewards Programme

Published

on

Kindly share this post

X has announced plans to discontinue its Revenue Sharing programme and introduce a new Original Content Rewards programme to reward creators for producing original content on the platform.

X Replaces Revenue Sharing wit New Creator Rewards Programme

The social media company announced the changes at the weekend in a post on its X Creators handle, saying the new programme would reward creators who contribute original content.

“Today, we’re introducing the Original Content Rewards Program, a new way to reward creators who bring original ideas, expertise, reporting, creativity, and commentary to X,” the company said.

X said it would stop accepting new enrolments into the Revenue Sharing programme from Friday, while existing participants would continue earning until September 7, 2026.

“Starting today, we’re no longer accepting new enrollments into Revenue Sharing,” it said.

Advertisement

According to the company, existing Revenue Sharing participants will receive three final payouts, with two scheduled for August 14 and August 28, while the final payment for earnings accrued through September 7 is expected around September 11.

X said existing Revenue Sharing participants would begin getting access to apply for the new programme from September 8, subject to meeting its eligibility requirements.

The first payout under the Original Content Rewards programme will be made on August 28, 2026, while existing Revenue Sharing creators who enrol in the new programme from September 8 will receive their first payment on September 25.

Under the new programme, eligible creators will earn from qualified impressions generated by their original content, with payments made every two weeks.

X defined qualified impressions as unique impressions from Premium users on the Home Timeline feed, where at least 50 per cent of a post is visible.

Advertisement

On the other hand, “The following are excluded from qualified impressions: impressions from the same account counted more than once per post; paid, promoted, or artificially generated impressions; and fraudulent impressions,” it said.

To qualify, creators must be at least 18 years old, live in a country where the programme is available, maintain an account in good standing and have either a personal or vusiness account.

They must also subscribe to X Premium, Premium+ or Premium Business, have at least 500 verified followers and record at least 500,000 Home Timeline impressions from verified users within the previous 90 days.

X said creators must also regularly post original content to remain eligible.

“We want to recognize creators who break news, share expertise, tell stories, create entertainment, and contribute meaningful perspectives to the conversation,” the company said.

Advertisement

The platform said original content could include threads, videos, memes, graphics, illustrations, reporting, analysis, commentary and reactions that add meaningful value to existing conversations.

It said creators who use content produced by others would need to add meaningful commentary, context, analysis, humour or creative transformation for such posts to qualify.

“Building on existing conversations is a core part of X, but simply reposting someone else’s content is not enough,” it said.

X said minor edits such as cropping, filters, borders, watermarks, speed adjustments or simple text overlays would generally not qualify as meaningful transformation on their own.

It also warned that content copied or substantially reproduced from another creator, content downloaded and re-uploaded from X or another platform without being the original author’s, automated content, disinformation and misleading content would be ineligible.

Advertisement

The company said accounts that violate the programme’s requirements could be temporarily or permanently removed from it, depending on the severity of the violation.

It added that creators would be responsible for ensuring they had the necessary rights, permissions or licences to use content created by others.

“Original content is content you personally create that reflects your own voice, perspective, expertise, or creativity,” X said.

The company said the new programme was intended to reward creators who make the platform more valuable by bringing original ideas and perspectives to its conversations.

“The Original Content Rewards Program is designed to reward the creators who start them, shape them, and move them forward,” it said.

Advertisement

Kindly share this post
Continue Reading

Trending