logo

BMW security lapse exposed sensitive company information, researcher finds

ID: 4ac22034-c93d-5248-ac94-7688f1d4faf7

STIX ID: report--4ac22034-c93d-5248-ac94-7688f1d4faf7

Feed Name: TechCrunch Security News

Threat Score
65/100

Date Published: 2024-02-14

Date Updated: 2026-04-23

Author: Carly Page

...
...

A publicly accessible Microsoft Azure development storage bucket belonging to BMW was discovered by a researcher to contain script files, private keys for cloud services across multiple regions, and database login credentials. BMW reported it fixed the misconfiguration in early 2024 and stated no customer data was affected, but it has not confirmed rotation of the exposed keys and there is no publicly confirmed evidence of malicious access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.