BlueBleed (Oct 2022): Misconfigured Azure Blob Storage Exposes Microsoft Customer Data
Retrospective: this article looks back at events from October 2022, written in 2026 with the benefit of hindsight.
In October 2022, threat intelligence company SOCRadar reported a data leak it called BlueBleed: a misconfigured Microsoft-owned Azure Blob Storage container had exposed business transaction data related to Microsoft customers and prospects.
What was exposed
SOCRadar said the data included proof-of-execution and statement-of-work documents, product orders and offers, customer email content, contact details and internal comments, involving tens of thousands of organizations. Microsoft confirmed the misconfigured endpoint, said it had been secured, and disputed the scale, stating that SOCRadar had greatly exaggerated the scope. Microsoft also criticized SOCRadar for making a search tool available that let people look up their organization in the data.
How it happened
Microsoft attributed the issue to a misconfigured endpoint in its own environment — not a vulnerability. Like many cloud data leaks, it involved storage that was accessible without proper authentication.
Why it mattered
- Cloud providers' own teams make configuration mistakes, just like customers.
- Business data is sensitive too. Sales documents, pricing and customer communications are valuable to competitors and attackers.
- Disclosure disputes between researchers and vendors complicate customer understanding of risk.
Lessons for Azure customers
- Disable anonymous blob access at the storage account level (
AllowBlobPublicAccessset to false). - Disable shared key authorization where possible and use Entra ID.
- Use private endpoints for storage holding internal data.
- Assign Azure Policy to prevent public storage.
- Monitor storage access with Defender for Storage.
In hindsight
Microsoft later changed defaults so anonymous blob access is disallowed for new storage accounts. BlueBleed, along with the 2023 SAS token exposure, kept Azure storage configuration on every assessment checklist.
- How to Audit Azure Storage Accounts for Public Access and Shared Keys How-To & Hardening
- Detecting Azure Blob Public Access: Defender for Cloud and Sentinel KQL Detection & Response
- CIO Brief: Storage Misconfiguration Is a Cloud-Agnostic Problem CIO Briefings