Skip to content
Techzine Global
  • Home
  • Topstories
  • Topics
    • Analytics
    • Applications
    • Collaboration
    • Data Management
    • Devices
    • Devops
    • Infrastructure
    • Privacy & Compliance
    • Security
  • Insights
    • All Insights
    • Agentic AI
    • Analytics
    • Cloud ERP
    • Generative AI
    • IT in Retail
    • NIS2
    • RSAC 2025 Conference
    • Security Platforms
    • SentinelOne
  • More
    • Become a partner
    • About us
    • Contact us
    • Terms and conditions
    • Privacy Policy
  • Techzine Global
  • Techzine Netherlands
  • Techzine Belgium
  • Techzine TV
  • ICTMagazine Netherlands
  • ICTMagazine Belgium
Techzine » News » Security » Private keys and logins BMW were stored in public Azure server
2 min Security

Private keys and logins BMW were stored in public Azure server

Floris Hulshoff PolFebruary 15, 2024 2:28 pmFebruary 15, 2024
Private keys and logins BMW were stored in public Azure server

A misconfiguration of a Microsoft Azure server at BMW leaked sensitive company information. This was discovered by a SOCRadar researcher during a routine Internet scan, reports TechCrunch.

According to TechCrunch, Can Yoleri, a security researcher at SOCRadar, discovered the misconfigured and thus open Azure server of German automotive group BMW. This happened during a routine scan of the internet. The so-called Azure “bucket” was located in BMW’s development environment and was accidentally configured as a public server instead of a private server. This made the information in the bucket readable.

Login credentials for multiple cloud services

In the open Azure bucket, the security researcher found sensitive information, including access information for Azure containers, secret keys to access private bucket addresses and details about other cloud services. More specifically, this would include private keys for BMW cloud services in China, Europe and the U.S. It also involved login details for the automotive group’s production and development databases.

It is unknown how long the bucket in question was open. The security researcher shared his findings with BMW.

Problem partially addressed

BMW indicated that the Azure bucket in question had indeed been open in response to the event. According to a spokesperson, it involved an Azure bucket in the company’s storage development environment. Customer data or other personal information was not leaked.

By early 2024, BMW would have resolved the issue. The company remains alert to possible misuse. The automaker would not comment on how long the bucket in question had been open and did not say whether malicious access to the exposed data had been gained in the meantime.

Researcher Yoleri stated in a reaction that the automotive group still has not revoked or updated all passwords or other login credentials. Thus, the automotive group has only made the Azure bucket private.

More misconfigurations in the automotive industry

By the way, BMW is not the only German automobile manufacturer that has recently inadvertently disclosed company-sensitive data. In January of this year, Mercedes-Benz accidentally left a private GitHub token open that provided unlimited access to company source code.

Read also: Internal data Mercedes-Benz was accessible due to public GitHub token

Tags:

Azure / BMW / Data leak / login credentials / misconfiguration

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

Stay tuned, subscribe!

Nieuwsbrieven*

Related

Dutch researcher discovers Fujitsu blunder: AWS keys and logins in public bucket

IBM: Cloud use makes Europe biggest target of hackers in 2023

Hackers sell data center login credentials of large multinationals

Cloud services Microsoft Azure in Texas were temporarily offline due to extreme weather conditions.

Editor picks

Why your SOC needs a ROC

Qualys CEO Sumedh Thakar dives into vulnerability, risk and the ROC

How attackers use Microsoft agents to steal OAuth tokens

AI agents are proving to be extremely resourceful. Among their discov...

Atlassian CTO on realistic AI: Rovo, data privacy and adoption

Organizations don't benefit from AI yet: how can they change that?

The true cost of a cloud outage

A week after the main AWS region went down, Microsoft Azure also expe...

Techzine.tv

Is ServiceNow competing with Salesforce? We talk to Amit Zavery

Is ServiceNow competing with Salesforce? We talk to Amit Zavery

Slack is evolving into a work operating system

Slack is evolving into a work operating system

Nutanix CTO explains their VMware alternative and multi-cloud strategy

Nutanix CTO explains their VMware alternative and multi-cloud strategy

In-depth conversation about Agentforce IT service and how it wants to change the ITSM market

In-depth conversation about Agentforce IT service and how it wants to change the ITSM market

Read more on Security

Palo Alto Cortex AgentiX gives SOAR much-needed AI update
Top story

Palo Alto Cortex AgentiX gives SOAR much-needed AI update

Cortex Cloud and Prisma AIRS get version 2.0

Sander Almekinders October 28, 2025
Docker fixes serious vulnerabilities in Compose and Desktop Installer

Docker fixes serious vulnerabilities in Compose and Desktop Installer

Docker has fixed two serious vulnerabilities in its software. A bug in Docker Compose allowed writing files o...

Mels Dees 2 days ago
EU diplomats targeted by Chinese attackers via Windows exploit

EU diplomats targeted by Chinese attackers via Windows exploit

The Chinese cyber threat UNC6384 was already known to target diplomats in Southeast Asia. Now it appears that...

Erik van Klinken 2 days ago
Why your SOC needs a ROC
Top story

Why your SOC needs a ROC

Qualys CEO Sumedh Thakar dives into vulnerability, risk and the ROC

Sander Almekinders 2 days ago

Expert Talks

Three Ways Secure Modern Networks Unlock the True Power of AI

Three Ways Secure Modern Networks Unlock the True Power of AI

AI is rapidly becoming the main driver of innovation for businesses, ...

Data Governance in the Cloud: Balancing Innovation and Regulation

Data Governance in the Cloud: Balancing Innovation and Regulation

The cloud has become the backbone of modern business, enabling rapid ...

How to Safeguard and Prepare Exchange Server against Natural Disasters?

It is critical to make sure that the Exchange Server is protected fro...

Minimizing liability is not the same as security: Lessons learned from Collin’s Aerospace cyberattack

Key points: A ransomware attack targeting the ARINC vMUSE syste...

Tech calendar

Discover Why Northern Europe Chooses Redgate Monitor

November 13, 2025

Dell Technologies Forum

November 13, 2025 Nieuwegein

BrickCon The Databricks Community Conference

December 3, 2025 Orlando, Florida

Appdevcon

March 10, 2026 Amsterdam

Webdevcon

March 10, 2026 Amsterdam

Dutch PHP Conference

March 10, 2026 Amsterdam

Whitepapers

Experience Synology’s latest enterprise backup solution

Experience Synology’s latest enterprise backup solution

How do you ensure your company data is both secure and quickly recove...

How to choose the right Enterprise Linux platform?

How to choose the right Enterprise Linux platform?

"A Buyer's Guide to Enterprise Linux" comprehensively analyzes the mo...

Enhance your data protection strategy for 2025

The Data Protection Guide 2025 explores the essential strategies and...

Strengthen your cybersecurity with DNS best practices

The white paper "DNS Best Practices" by Infoblox presents essential g...

Techzine Global

Techzine focusses on IT professionals and business decision makers by publishing the latest IT news and background stories. The goal is to help IT professionals get acquainted with new innovative products and services, but also to offer in-depth information to help them understand products and services better.

Follow us

Twitter
LinkedIn
YouTube

© 2025 Dolphin Publications B.V.
All rights reserved.

Techzine Service

  • Become a partner
  • Advertising
  • About Us
  • Contact
  • Terms & Conditions
  • Privacy Statement