Researchers find 1K+ web apps, from Ford, American Airlines, and others, mistakenly exposed 38M records stored on Microsoft's Power Apps service
Misconfigured Power Apps from Microsoft led to more than a thousand web apps accessible to anyone who found them. Source: UpGuard Data Breach Research .
Context & Ripple Effects
The Power Apps exposure fits a longer pattern in which application teams, rather than a platform breach, leave cloud-hosted data reachable through configuration errors. A prior review identified misconfigured Firebase databases across thousands of mobile apps, while a 2021 analysis found cloud-service configuration problems among apps connecting to AWS or Azure.
That history matters because Power Apps extends the same access-control problem into business web applications used by named enterprises, putting discovery and auditing of publicly reachable data stores at the center of the response.
First-order effects
- Ford, American Airlines, and the other organizations behind the affected apps must identify exposed records and correct the Power Apps configurations that made them publicly accessible.
- Microsoft faces immediate scrutiny of Power Apps' configuration safeguards, since more than 1,000 web apps were reportedly reachable by anyone who located them.
Second-order effects
- Organizations using low-code and cloud services will face pressure to audit access settings more systematically, reinforced by the earlier finding of cloud-service misconfigurations in mobile apps.
- Cloud platforms and their customers increasingly share the security burden: platform defaults and warnings matter, but customers control whether individual applications expose records.
Third-order effects
- If disclosures continue across Firebase, Power Apps, and other hosted application services, data exposure will be treated less as an isolated vendor failure and more as a recurring governance risk of self-service cloud development.
- The durable shift is toward access controls and configuration review becoming core operational requirements as business teams publish applications without traditional infrastructure ownership.
The trend: Cloud and low-code adoption is moving the data-security boundary from centrally managed infrastructure to the access settings maintained by individual application teams.