Skip to main content

Company intelligence

Microsoft cybersecurity incidents and threat signals

microsoft.com

Microsoft logo

Microsoft is a technology company that develops productivity software, cloud services, operating systems, business applications, devices and AI products.

Company country

United States

Facts last verified July 23, 2026

3

Published signals

currently linked to this company

0

Last 28 days

recent published signals

2

Last 90 days

recent published signals

0

High or critical

confidence classifications

July 22, 2026

Latest report

most recent published signal

Explore related intelligence

Explore this reporting from another angle

Based on all published signals currently linked to Microsoft. Affected countries come from victim data; the company country above remains a separate profile fact. Counts describe this reporting set, not overall incident prevalence.

Company signals

All published signals involving Microsoft

Microsoft logoRansomware
Medium

Malicious 'Edgecution' Extension Exploits Microsoft Edge Native Messaging for Ransomware Deployment

Security researchers reported on June 25, 2026, the discovery of a new malware campaign dubbed 'Edgecution,' which utilizes a malicious Microsoft Edge extension to deploy ransomware and a Python-based backdoor. The extension abuses the Native Messaging API to escape the browser sandbox and establish a persistent system-level executor. Attackers are reportedly using Microsoft Teams for social engineering, directing victims to fake 'Outlook Updates Management Console' websites to trick them into installing the malicious extension. This campaign is believed to be operated by an Initial Access Broker (IAB) linked to the 'Payout Kings' ransomware operation.

Microsoft
Microsoft logo
Medium

Microsoft Accused of Leaking Dutch Civil Servants' Data to US Government

Microsoft has been accused of leaking data belonging to Dutch civil servants, specifically those working for the Authority for Consumers and Markets (ACM) and the Dutch Data Protection Authority (AP), to the US House of Representatives. The leaked data includes emails, minutes, and invitations with unredacted names.

Microsoft
Microsoft logo
Medium

ICCL Launches Class Action Against Microsoft Over 'Real-Time Bidding' Data Breach

Class action will target “Real-Time Bidding” (RTB) data breach in Microsoft’s advertising system, and is anticipated to affect Microsoft’s operations across the EU 26 May 2025 -  In the first action of its kind in Ireland, the Irish Council for Civil Liberties (ICCL) will today apply to the High Court to launch a class action lawsuit against Microsoft. The case is intended to target the very large “Real-Time Bidding” (RTB) data breach within Microsoft’s advertising system. ICCL is taking the legal action on behalf of all affected people in Ireland under the new EU Collective Redress Directive. The organisation hopes to force Microsoft to bring its systems into compliance with the EU’s General Data Protection Regulation (GDPR). This application comes on the seven year anniversary of the GDPR's introduction on 25 May 2018. The outcome of this litigation is anticipated to affect Microsoft’s operations across the European Economic Area as the company’s European headquarters are based in Ireland. Users of Office, Windows, Xbox and the general internet are affected Microsoft’s RTB system operates behind the scenes on websites and apps to match advertising to specific people. Users of popular Microsoft products and services, including Windows, Xbox, web-based Office (Word, Excel and Outlook), the Edge web browser that is pre-installed with Windows, and websites and apps that use Microsoft’s Xandr advertising technology, are affected. Dr Johnny Ryan, Director of ICCL’s Enforce unit, is leading the case and said: “People’s intimate secrets such as their relationship, work and financial status are broadcast by Microsoft into the Real-Time Bidding advertising system. That system is a black hole of data open to any malicious actor and represents a huge data breach of millions of people’s information”. Very sensitive data about people exposed, including national security personnel ICCL Enforce investigations have revealed the extraordinary sensitivity of the data that Microsoft exposes. Posing as a data buyer, ICCL Enforce obtained thousands of RTB data “segments” about Irish people. These include information such as whether a person gambles, their finances and debt, and even such sensitive information as whether the person works in a sensitive national security role. “Microsoft has no way of knowing what happens to the personal data after it broadcasts. This a data breach, pure and simple. Microsoft is exposing us all individually to malicious profiling and discrimination, and in doing so it is also undermining European security”. ICCL is represented by James Doherty SC, Sean O’Sullivan BL and Ahern Rudden Quigley. See explainers about RTB at https://iccl.ie/rtb/ The Irish High Court granted permission on May 26, 2025 for the country's first class action lawsuit, marking a significant milestone in European data protection enforcement six days after the seventh anniversary of GDPR implementation. The Irish Council for Civil Liberties (ICCL) secured approval to launch proceedings against Microsoft under the EU Collective Redress Directive. The case targets alleged violations within Microsoft's Real-Time Bidding (RTB) advertising system, which the organization characterizes as constituting a massive data breach affecting millions of users across Europe. According to ICCL's application, the lawsuit focuses on Microsoft's RTB operations that process data from users across multiple platforms. Users of popular Microsoft products and services, including Windows, Xbox, web-based Office (Word, Excel and Outlook), the Edge web browser that is pre-installed with Windows, and websites and apps that use Microsoft's Xandr advertising technology, are affected, the organization stated. The case emerges from ICCL's investigation into RTB data practices, which revealed extensive categorization of sensitive personnel. The organization's research identified thousands of RTB data "segments" about Irish people obtained through posing as a data buyer. These segments included information about gambling habits, financial status, and employment in sensitive national security roles. Dr Johnny Ryan , Director of ICCL's Enforce unit, leads the case. "People's intimate secrets such as their relationship, work and financial status are broadcast by Microsoft into the Real-Time Bidding advertising system. That system is a black hole of data open to any malicious actor and represents a huge data breach of millions of people's information", Ryan stated. Microsoft's controversial Xandr acquisition and sunset The timing of this legal action coincides with Microsoft's decision to discontinue its demand-side platform (DSP), Microsoft Invest (formerly Xandr, formerly AppNexus) . According to Microsoft Advertising Corporate Vice President Kya Sainsbury-Carter, the company announced on May 14, 2025 that it will discontinue Microsoft Invest effective February 28, 2026. Microsoft acquired Xandr from AT&T in June 2022 , completing a deal first announced in December 2021. AT&T had previously acquired AppNexus in 2018 for a reported $1.6 billion. The original AppNexus platform, founded in 2007 by Brian O'Kelley and Mike Nolet, was widely recognized for providing unprecedented transparency into fee structures and money flows throughout the advertising supply chain. According to Sainsbury-Carter's announcement, Microsoft is "exclusively focusing our buy-side advertising technology investments on the Microsoft Advertising Platform" starting in 2026. The company stated its commitment to "more private and personalized advertising experiences for a more agentic and conversational world is not achievable with the industry's current DSP model." This strategic shift away from traditional DSP operations removes one of the most transparent options in the programmatic ecosystem. AppNexus had established itself as a champion of transparency, with co-founder Brian O'Kelley positioning the company as providing advertisers with visibility into fee structures long before it became an industry priority. Announcement from Kya Sainsbury-Carter, Corporate Vice President at Microsoft Advertising - May 14, 2025 At Microsoft Advertising, we believe that the future of digital engagement is conversational, personalized, and agentic. Our strategic vision is rooted in the transformative power of generative AI to create entirely new possibilities in advertising, unlocking better outcomes between people, brands, publishers, and ad platforms. We are entering a new era—one defined by conversational AI experiences, agentic systems that simplify decision making and bring brands closer to people, and predictive design models that fundamentally reshape what people expect from digital services. This new era will be enabled by purpose-built AI-powered advertising platforms that make personalized advertising simple.

Microsoft

FAQ

Questions about Microsoft cybersecurity reporting

What does the Microsoft page include?

It combines a reviewed organization profile with all current published Shadow Tier signals explicitly linked to Microsoft.

Does every mention of Microsoft appear here?

No. A signal must contain a reliable company connection and meet the publication criteria; incidental or ambiguous mentions are excluded.

Why can the incident count change?

The page follows current published reporting. Counts change as new evidence is added, classifications are reviewed, or older signals leave the reporting window.