Microsoft Bing app may have suffered a huge data leak Bing Search app


An unsecured server may have led to a massive data leak in Microsoft’s Bing mobile app according to a new report from the online security site WizCase.
The site’s online security team, led by white hat hacker Ata Hakcil, discovered the unsecured server online and traced it back to Bing’s mobile app.
To confirm the team’s findings, Hakcil downloaded the app and ran a search for “Wizcase”. He then looked through the data stored on the unsecured server to find that his information, including search queries, device details and GPS coordinates, was there, proving that the exposed data was coming directly from Bing’s mobile app.
The exposed data on the server includes search terms in clear text, the exact time searchers were executed, location coordinates, Firebase Notification Tokens, coupon data, a partial list of the URLs users visited from the search results, device model, operating system and three separate unique ID numbers (ADID, deviceID and devicehash) assigned to each user found in the data.
Exposed server
Hakcil and his team began their investigation after discovering a 6.5TB server that was growing by as much as 200GB per day. Based on the amount of data added to the server each day, WizCase believes it’s safe to speculate that anyone who used Bing’s mobile app to conduct a search while the server was exposed is at risk as the team saw records of user searches from more than 70 countries.
According to the company’s scanner, the server was password protected until the first week of September and was exposed online without a password for two full days. WizCase then reached out to Microsoft and reported the data leak to the Microsoft Security Response Center (MSRC) and the server was secured a few days later.
Based on its observations, the team believes that the server was targeted by a Meow attack that deleted nearly the entire database. A second Meow attack was then observed a few days later.
In addition to these attacks, the data was exposed to cybercriminals while the server was exposed online which could put Bing mobile users at risk from a number of threats including blackmail, phishing and even physical attacks as their physical locations could be determined based on the GPS coordinates of their mobile devices.
In a blog post about the exposed server, web security expert at WizChase Chase Williams explained how the team’s discovery highlighted the ways in which search engines are being used for nefarious activities online, saying:
“As ethical hackers, we don’t have the resources to identify these people and turn them over to the authorities. Yet, this discovery revealed how many predators and dangerous people are using search engines to find their next victims and what websites they are visiting.”
Via WizChase
An unsecured server may have led to a massive data leak in Microsoft’s Bing mobile app according to a new report from the online security site WizCase. The site’s online security team, led by white hat hacker Ata Hakcil, discovered the unsecured server online and traced it back to Bing’s…
Recent Posts
- The GSA is shutting down its EV chargers, calling them ‘not mission critical’
- Lenovo is going all out with yet another funky laptop design: this time, it’s a business notebook with a foldable OLED screen
- Elon Musk’s first month of destroying America will cost us decades
- The first iOS 18.4 developer beta is here, with support for Priority Notifications
- Fortnite’s new season leans heavily on heist mechanics
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010