Looking for a complete Microsoft data breaches list? This page answers common searches like "Microsoft hacked," "Microsoft breach history," and "list of Microsoft data breaches" with a verified timeline, record counts, root causes, and step-by-step guidance if you may have been affected.
Microsoft data breach history: Hotmail dumps, Power Apps misconfigurations, and LinkedIn-scale scraping—Microsoft’s breach history spans consumer, cloud, and enterprise identity. BreachHistory indexes 19 verified or attested incidents tied to Microsoft, spanning 2010–2024. This page is a complete, searchable timeline—not a single event—linking every catalog row with context on scale, root cause, and what users should do when a new Microsoft notice drops.
Why Microsoft stays on breach trackers
Global tech brands combine massive user bases, high-value intellectual property, and complex supply chains. Attackers target Microsoft for credentials, source code, CRM exports, and employee directories. When you read headlines about "Microsoft hacked," the incident may be a consumer PII leak, a developer artifact exposure, or a third-party SaaS tenant breach—each with different remediation steps.
Data breaches list — Microsoft
Below are the major incidents in our catalog, newest first. Record counts use company, regulator, or Have I Been Pwned attestation where available; actor-only marketing shows as "Unverified / not disclosed."
- 2024 — Russian SVR group breach of corporate email (Cozy Bear) (Unverified / not disclosed records)
- 2023 — 60k State Department emails stolen (Storm-0558) (60K+ records)
- 2023 — Chinese hackers breach U.S. agencies via Microsoft Cloud (Storm-0558) (Unverified / not disclosed records)
- 2022 — BlueBleed: 548k+ users exposed on misconfigured endpoint (548K+ records)
- 2022 — Lapsus$ group breaches Microsoft (Azure DevOps) (Unverified / not disclosed records)
- 2021 — 38M records exposed via Power Apps misconfiguration (38M+ records)
- 2021 — Azure Cosmos DB vulnerability exposes customer databases (Unverified / not disclosed records)
- 2021 — 500M LinkedIn users' data scraped and sold (500M+ records)
- 2021 — Exchange Server zero-days lead to 60k+ hacks worldwide (60K+ records)
- 2020 — SolarWinds supply chain (nation-state) (Unverified / not disclosed records)
- 2020 — SolarWinds supply chain attack (18k customers, including Microsoft) (18K+ records)
- 2019 — 250M+ customer support records exposed (misconfigured DB) (250M+ records)
- 2019 — Compromised support agent credentials — webmail access (Unverified / not disclosed records)
- 2016 — Hundreds of Skype accounts hacked for spam (Unverified / not disclosed records)
- 2016 — 33M Hotmail credentials found for sale online (33M+ records)
Biggest and most consequential incidents
500M LinkedIn users' data scraped and sold
Personal data on 500M+ LinkedIn users posted for sale. LinkedIn stated data was scraped from publicly available profiles; included emails and phone numbers. Full incident record →
250M+ customer support records exposed (misconfigured DB)
Misconfigured internal customer support database left 250M records exposed Dec 5–31, 2019. PII, support conversations, IPs; data from 2005–2019. Full incident record →
38M records exposed via Power Apps misconfiguration
Misconfigured Microsoft Power Apps portals led to at least 47 organizations exposing 38M+ records (American Airlines, Ford, NY MTA, etc.). Data included COVID-19 info, SSNs, addresses. Discovered by UpGuard. Full incident record →
33M Hotmail credentials found for sale online
272M stolen credentials found; ~33M were Hotmail. Cache surfaced when a Russian hacker advertised the trove for under $1. Full incident record →
By the numbers (catalog snapshot)
- 19 incidents indexed under Microsoft on BreachHistory
- 821.7M+ combined attested records across rows with disclosed numerators (many incidents overlap or count emails—not unique people)
- 2021 — year of the largest attested row in our catalog
Patterns in Microsoft's breach history
- Credential and session theft — Phishing, stuffing, and OAuth token abuse recur across tech platforms.
- Cloud misconfiguration — S3 buckets, misconfigured APIs, and file shares expose data without a traditional "hack."
- Extortion without precise counts — Ransomware and leak-site actors often publish before victims confirm scope.
- Supply-chain spillover — npm, SDK, and CRM tenant breaches affect Microsoft customers even when corporate HQ databases stay intact.
What to do if you used Microsoft
- Enable multi-factor authentication on every Microsoft account and linked SSO identity.
- Check Have I Been Pwned when new Microsoft headlines appear.
- Rotate passwords that were reused on email, banking, or work SSO.
- Watch for phishing that cites real breach details (order numbers, usernames) to appear legitimate.
- Follow official Microsoft security communications—not SMS links from unknown numbers.
Related searches
- Microsoft data breach list
- Has Microsoft been hacked?
- Microsoft hack history
- Microsoft data leak timeline
- How many times has Microsoft been breached?
- Microsoft breach records on BreachHistory
FAQ
How many data breaches has Microsoft had?
BreachHistory indexes 19 verified or attested Microsoft data breaches spanning 2010–2024. Counts vary when researchers merge scraping, misconfiguration, and ransomware as separate events.
What is the biggest Microsoft data breach?
The largest attested incident in our catalog is 500M+ records (500M LinkedIn users' data scraped and sold). See the full timeline for sources and remediation details.
Has Microsoft been hacked?
Yes — Microsoft appears on breach trackers with 19 indexed incidents including 500M LinkedIn users' data scraped and sold. This page links every catalog row with primary sources and what users should do if affected.
Does Microsoft send data breach notifications?
Regulated markets require consumer notices for many PII events. Not every source-code or scraping story triggers email alerts—read each incident row for notification status.
Explore every Microsoft incident on BreachHistory
Browse the full catalog: Microsoft breach records
Compiled from BreachHistory data/breaches.json and primary sources linked on each incident page. Updated 2026-06-15.