/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

A researcher found a now-secure US DOD Azure database without a password for two weeks that had years' worth of military emails with sensitive personnel info

TechCrunch Zack Whittaker

Context & Ripple Effects

This incident slots into two overlapping histories. One is the military's own record with cloud storage: back in [[a:924455|2017, a researcher found 100GB of US intelligence data from the Army and NSA sitting on an unsecured AWS server]], making this DOD exposure a repeat of the same class of mistake on a different hyperscaler six years later. The other is Microsoft's security track record on Azure specifically — researchers later found [[a:862612|an exposed Azure server carrying Microsoft staff credentials used to reach internal systems]], and the stolen-key attack that compromised roughly 25 organizations' State Department-hosted email had already put the DOD's largest cloud supplier under scrutiny before this database surfaced.

The detail that matters here is duration: years of accumulated military email with personnel data sat reachable by anyone who found the endpoint, unprotected for two weeks before the researcher reported it. That turns a configuration error into a potential intelligence-collection opportunity, not just a hygiene problem.

First-order effects

  • Service members whose emails and personnel details were in the database spent two weeks exposed to anyone who discovered the addressless endpoint; the immediate work is scoping what was accessed and whether adversaries found it before the researcher did.

Second-order effects

  • Every new finding tightens the screw on Microsoft's government-cloud business — following the State Department key theft and the exposed internal-credentials server, each incident gives DOD procurement and oversight bodies more grounds to demand configuration attestation and continuous auditing rather than trusting the vendor's defaults.

Third-order effects

  • If misconfigured storage keeps producing these leaks across both AWS and Azure, the likely structural outcome is that government cloud contracts shift toward secure-by-default mandates and independent verification layers, moving the burden of basic hygiene off individual teams and onto the platform contract itself.

The trend: Government and military data hosted on hyperscaler clouds keeps leaking through elementary misconfigurations, steadily converting cloud security from a customer responsibility into a contractual and regulatory requirement.

Discussion

  • @zackwhittaker Zack Whittaker on x
    Breaking: The U.S. Department of Defense secured an exposed server on Monday that was spilling terabytes of internal U.S. military emails to the internet for two weeks. The server wasn't protected with a password, a security researcher told TechCrunch. https://techcrunch.com/...
  • @canariesblue @canariesblue on x
    DOD to China: Hold my beer.. WE left our server unsecured without a password. 😅🤣😅🤣 China: OK, but you have to admit, it was entertaining to watch our balloon on the news each night. https://twitter.com/...
  • @k8em0 @k8em0 on x
    So tell me again that having a bug bounty or Vulnerability Disclosure Program is any indicator of security maturity & I'll show you a missing people/process/tech security program. https://twitter.com/...
  • @politicalshort Nick Short on x
    The Department of Defense secured an exposed server on Monday that was spilling internal military emails to the open internet for the past 2 weeks...it was only secured because TechCrunch alerted the government on Sunday. The incompetency is astounding. https://techcrunch.com/...
  • @repdanbishop Rep. Dan Bishop on x
    How does this sort of thing keep happening? It seems clear that there are broad issues with data security at federal agencies. https://techcrunch.com/...
  • @warlorddilley Brenden Dilley on x
    There is no way this was an accident... #Espionage https://twitter.com/...