Even the US Department of Defence is not immune to data breaches as 20,000 individuals are notified of a Microsoft cloud email leak

3d image of an email icon in space
(Image credit: Getty Images)

A data breach can be an embarrassing admission for a company, but when it comes to a leak of government controlled data, particularly in regards to the sort of sensitive information held by national security agencies and the military, the stakes can become a lot higher. It appears that the US Department of Defence has had to make just such an admission, as it notified an estimated 20,600 individuals that some of their email messages and potentially personal information contained within had been exposed to the internet at large.

The breach occurred last year between February 3 and February 20, and has been attributed to an unsecured US government cloud email server hosted on Microsoft's cloud for government customers (via TechCrunch). The server was believed to be accessible during this period without password access, meaning anyone with the public IP address could view the emails contained within using nothing but a web browser.

As a result the DOD has since sent breach notification letters to the estimated 20,600 individuals affected, which is probably a pretty hair-raising thing to receive in your mail box if you'd been working under the fairly reasonable assumption that your communications with or within the US Department of Defence were kept secure.

The leak is likely down to a simple misconfiguration of server settings, but as to the content within and further information, the DOD remains tight-lipped. Spokesperson Cdr. Tim Gorman said "As a matter of practice and operations security, we do not comment on the status of our networks and systems. The affected server was identified and removed from public access as of February 20, 2023, and the vendor has resolved the issues that resulted in the exposure".

Thinking of upgrading?

Windows 11 Square logo

(Image credit: Microsoft)

Windows 11 review: What we think of the latest OS.
How to install Windows 11: Our guide to a secure install.
Windows 11 TPM requirement: Strict OS security.

While this isn't the greatest look for Microsoft's cloud platform, and a bit of an embarrassing admission, data breaches on a much larger scale than this from a variety of vendors have become depressingly common. 

The "mother of all breaches" containing over 26 billion records of private user data was discovered back in January, while popular US communications carrier Verizon has also hit the headlines recently with a breach of 63,000 employees personal data.

Still, you could be forgiven for assuming that data kept by government agencies was kept in a more secure fashion, but the truth is these agencies still rely on cloud based solutions provided by major companies, and those solutions are just as liable to accidental exposure or a malicious attack as the rest of them. 

Whether it's a coordinated effort to steal data or something as simple as the misconfiguration of some server settings, the truth is that once you pass your information onto the interwebs, no matter who is handling the data, there is a real risk it can be exposed, even if you follow all the best practices yourself.

Andy Edser
Hardware Writer

Andy built his first gaming PC at the tender age of 12, when IDE cables were a thing and high resolution wasn't—and he hasn't stopped since. Now working as a hardware writer for PC Gamer, Andy's been jumping around the world attending product launches and trade shows, all the while reviewing every bit of PC hardware he can get his hands on. You name it, if it's interesting hardware he'll write words about it, with opinions and everything.

Read more
Kinzie, in an FBI jacket, uses a computer with the logo of the Third Street Saints on it
Have I Been Pwned adds over 284 million compromised passwords from latest breach
Microsoft Windows 11
If you installed Windows 11 with certain security updates and a USB stick, you may not get any more security updates warns Microsoft
Image manipulated symbolic alegory pointing into the mystery of being.
Deep trouble: Infosec firm finds a DeepSeek database 'completely open and unauthenticated' exposing chat history, API keys, and operational details
Mister Fantastic giving a thumbs up
A Marvel Rivals player has uncovered 'one of the most dangerous vulnerabilities a game can have' that'll let cheaters take over your PC and find your passwords
An FBI wanted poster for alleged hacker Zhou Shuai.
US Justice Dept announces $10 million bounty on at-large 'hacker-for-hire' cabal it says targeted China critics, religious missionaries, and the Treasury
Path of Exile 2 early access class key art
Around 66 accounts in Path of Exile 2 were compromised, due to a one-two punch of an old unused Steam account and a backend bug
Latest in Security
An FBI wanted poster for alleged hacker Zhou Shuai.
US Justice Dept announces $10 million bounty on at-large 'hacker-for-hire' cabal it says targeted China critics, religious missionaries, and the Treasury
Kinzie, in an FBI jacket, uses a computer with the logo of the Third Street Saints on it
Have I Been Pwned adds over 284 million compromised passwords from latest breach
A still from a YouTube video of Senator Mark Warner speaking
Telecoms hack on US government officials is 'worst in nations history' and 'the barn door is still wide open' says senator
HDMI cable
Hackers can wirelessly spy on your display by collecting HDMI signal leaks and churning them through an AI, but I wouldn't break out the tin foil just yet
Computer code and text displayed on computer screens. Photographer: Chris Ratcliffe/Bloomberg
Forcing users to periodically change their passwords should go the way of the dodo according to the US government
An original Apple Macintosh Model M0001, as they celebrate 40th anniversary, is on display in between 2024 Apple models at the independent Apple products store chain Amac, on January 24, 2024 in Utrecht, The Netherlands. Based on the Motorola 68000 microprocessor, the Macintosh was the first successful mouse-driven computer with a graphical user interface.
Major browser providers scramble to patch an 18-year-old vulnerability affecting MacOS and Linux systems but Windows remains gloriously immune
Latest in News
The heroes are attacked by monsters
Pillars of Eternity is getting turn-based combat to mark its 10th anniversary, and that means PC Gamer editors will soon be arguing about combat mechanics again
Image of Ronaldo from Fatal Fury: City of the Wolves trailer
It doesn't really make sense that soccer star Ronaldo is now a Fatal Fury character, but if you follow the money you can see how it happened
Junah beginning a battle in Metaphor: ReFantazio.
Today's RPG fans are 'very sensitive to feeling like they wasted time' when they die, says Metaphor: ReFantazio battle planner—but Atlus still made combat hard anyway
Image of Cersei Lanniser from Game of Thrones: Kingsroad Steam early access trailer
A new Game of Thrones RPG is coming to Steam today with a cast of 'familiar faces,' which is good because it's really the only way to tell it's a GoT game at all
The new Prime Asset featured in the upcoming update for the Outlast Trials.
The Outlast Trials puts its already paranoid players under surveillance for a time-limited story event
A Viera looking confused in Final Fantasy 14.
Old armor continues to fall victim to Final Fantasy 14's bizarre two-channel dye system, unless you're super into changing the colour of teeny-tiny eyelets: 'Why even bother at this point?'