Microsoft’s file storage site lets anyone access users’ sensitive personal details extraordinarily easily
I was able to track down financial records, phone numbers, CVs, visa application forms and passport scans within a couple of minutes
Your support helps us to tell the story
From reproductive rights to climate change to Big Tech, The Independent is on the ground when the story is developing. Whether it's investigating the financials of Elon Musk's pro-Trump PAC or producing our latest documentary, 'The A Word', which shines a light on the American women fighting for reproductive rights, we know how important it is to parse out the facts from the messaging.
At such a critical moment in US history, we need reporters on the ground. Your donation allows us to keep sending journalists to speak to both sides of the story.
The Independent is trusted by Americans across the entire political spectrum. And unlike many other quality news outlets, we choose not to lock Americans out of our reporting and analysis with paywalls. We believe quality journalism should be available to everyone, paid for by those who can afford it.
Your support makes all the difference.Users of Microsoft’s Docs.com document storage service are being warned that search functionality allows anyone to access their uploaded files.
Without even signing in to the site, I was able to track down extremely sensitive personal information, including bank details, phone numbers, CVs, visa application forms and passport scans, all within a couple of minutes.
It’s an extraordinarily worrying issue, which was discovered by security researchers and first reported by ZDNet.
However, Microsoft hasn’t made a mistake, nor has Docs.com been targeted by hackers.
Rather, all files uploaded to Docs.com are stored publicly by default, and it appears that many users simply aren’t aware of this.
Microsoft is aware of the issue and temporarily removed the search bar from the Docs.com home page. However, that has now returned.
Files stored on Docs.com can also be found through Google and Bing searches.
The company has, however, now created a warning box that appears before users upload documents publicly.
“Docs.com lets customers showcase and share their documents with the world,” a Microsoft spokesperson told Ars Technica.
“As part of our commitment to protect customers, we're taking steps to help those who may have inadvertently published documents with sensitive information. Customers can review and update their settings by logging into their account at www.docs.com.”
If you have anything stored publicly on Docs.com, we’d recommend deleting it as soon as possible. You can then re-upload it privately if you wish.
Join our commenting forum
Join thought-provoking conversations, follow other Independent readers and see their replies
Comments