A significant data breach has been uncovered by cybersecurity researcher Aaron Costello, revealing that 1.1 million NHS employee records were leaked online. The breach occurred due to improper configuration settings in Microsoft Power Pages, a widely-used platform for building websites. The exposed records included sensitive personal information such as email addresses, phone numbers, and home addresses of NHS staff. The vulnerability was discovered by Costello, who works with the cybersecurity firm AppOmni, highlighting the risks associated with poorly configured cloud-based platforms.
Costello, known for his previous findings of similar vulnerabilities, had previously uncovered a glitch in the Health Service Executive (HSE) Covid vaccination portal, which left the data of one million individuals exposed. In this case, the improper configuration of Microsoft Power Pages allowed unauthorized access to the NHS employee records, bringing to light the need for better security protocols in platforms storing sensitive information. The breach not only affects the privacy of healthcare workers but also raises broader concerns about the security of cloud-based platforms used by millions around the world.
Microsoft Power Pages is utilized by over 250 million users globally, underscoring the scale of the potential exposure. The incident points to the importance of regularly reviewing and securing cloud-based platforms, particularly those handling personal data. With the NHS being a critical institution in the UK, the breach puts a spotlight on the vulnerability of even the most essential services to data leaks. The exposed information could lead to a variety of risks, including identity theft and phishing attacks targeting NHS employees.
As of now, both Microsoft and the NHS are working to address the issue, but the breach serves as a wake-up call to organizations that rely on cloud-based platforms for storing sensitive data. Costello’s findings continue to highlight the ongoing need for cybersecurity professionals to scrutinize platform configurations and ensure they are properly secured against unauthorized access. Moving forward, this breach reinforces the critical need for stringent security measures and continuous monitoring of online platforms to protect personal information and prevent future data leaks.
Reference: