Microsoft Data Breach History
WebsiteMicrosoft Corporation is an American multinational technology corporation. Fortune 500.
This page shows all data breaches of Microsoft. View the complete breach timeline, records exposed, root causes, and AI breach risk score. BreachHistory tracks disclosed data breaches worldwide.
Data Breach Timeline — All Microsoft Breaches
- 2026 2026 Microsoft Azure/M365 — LSHIY password-spray campaign bypasses MFA via ROPC (Jun) 78 records Share
- 2025 2025 Microsoft 365 Copilot "EchoLeak" — zero-click AI data exfiltration (CVE-2025-32711) Unknown records Share
- 2024 Russian SVR group breach of corporate email (Cozy Bear) Unknown records Share
- 2024 2024 — Source code Unknown records Share
- 2023 60k State Department emails stolen (Storm-0558) 60.0K records Share
Microsoft Data Breach Summary
This page tracks the Microsoft data breach history and cybersecurity incidents affecting Microsoft (United States). BreachHistory currently indexes 25 publicly disclosed or catalogued incidents spanning 2010 through 2026, with approximately 846.7 million records reported as exposed across all indexed events. These totals may include overlapping datasets or third-party estimates and should not be interpreted as unique affected users.
The Microsoft breach timeline includes major data breaches, cyber attacks, data leaks, credential exposures, API abuse, and other security incidents. Each incident provides details on the estimated records exposed, attack method, affected data types, and supporting public sources. Currently, 0 incidents are company-confirmed.
Largest Microsoft Data Breaches
The largest indexed incidents include the 2021 500M LinkedIn users' data scraped and sold, the 2019 250M+ customer support records exposed (misconfigured DB), and the 2021 38M records exposed via Power Apps misconfiguration, along with additional historical incidents involving exposed passwords, public databases, and large-scale data scraping. Record counts originating from threat actors or leak sites should be treated as estimates unless confirmed by Microsoft or a regulator. Below is the list of large data breaches:
- 2021 500M LinkedIn users' data scraped and sold — about 500.0M records exposed · Catalogued incident
- 2019 250M+ customer support records exposed (misconfigured DB) — about 250.0M records exposed · Catalogued incident
- 2021 38M records exposed via Power Apps misconfiguration — about 38.0M records exposed · Catalogued incident
- 2016 33M Hotmail credentials found for sale online — about 33.0M records exposed · Catalogued incident
- 2020 2020 — Microsoft: Poor security / misconfiguration, 25,000,000 records — about 25.0M records exposed · Catalogued incident
- 2022 BlueBleed: 548k+ users exposed on misconfigured endpoint — about 548.0K records exposed · Catalogued incident
- 2023 60k State Department emails stolen (Storm-0558) — about 60.0K records exposed · Catalogued incident
- 2021 Exchange Server zero-days lead to 60k+ hacks worldwide — about 60.0K records exposed · Catalogued incident
What Information Was Exposed?
Depending on the incident, exposed data may include email addresses, passwords and login credentials, Social Security numbers and national IDs, phone numbers, names, physical addresses, and other personal information (PII). The exact data varies between incidents, so review each breach page before assuming your information was affected.
Microsoft Data Breach 2026
At the time of this update, BreachHistory catalogues 1 2026 incident related to Microsoft. Most recent entry: 2026 Microsoft Azure/M365 — LSHIY password-spray campaign bypasses MFA via ROPC (Jun). New incidents are added as official disclosures, regulatory filings, or credible cybersecurity reports become available.
What To Do If You Were Affected
If you believe your account may have been involved in a Microsoft data breach, change any reused passwords, enable multi-factor authentication (MFA), monitor your account for suspicious activity, and be cautious of phishing emails or fake breach notifications.
This Microsoft breach history is maintained by BreachHistory using public disclosures, regulatory filings, security research, and clearly labelled third-party claims. For the complete breach timeline, records exposed, incident details, and AI Breach Risk Score, explore the sections on this page.