Expo 2025 Data Leak: Microsoft 365 Account of Contractor Hacked

Photo: ITmedia
Quick answer
A Microsoft 365 contractor account was hacked, potentially exposing personal data of Expo 2025 participants, including organizers and speakers, as well as corporate email content and attachments.
Organizers of Expo 2025, the international exhibition set to take place in Osaka, Japan, have reported a potential leak of confidential data. The incident stemmed from unauthorized access to a Microsoft 365 account belonging to a subcontractor hired to assist with event preparations.
According to preliminary findings, attackers may have gained access to personal information of exhibition participants, including organizers and invited speakers. Email content and attachments stored in the account were also compromised. While the organizers did not specify which data was exposed, they confirmed that an investigation has begun.
This incident underscores the vulnerabilities in IT supply chains for large-scale events. Even with strict security requirements for primary contractors, risks can arise at the subcontractor level, where data protection controls may not be as stringent. Experts recommend enhancing monitoring of corporate system access and implementing multi-factor authentication for all project participants.
Common questions
- What data may have been exposed in the Expo 2025 leak incident?
- The breach may have compromised personal data of exhibition participants, including organizers and speakers, as well as email content and attachments from the hacked Microsoft 365 account.
- Who is responsible for the Expo 2025 data leak?
- The incident resulted from unauthorized access to a subcontractor’s Microsoft 365 account handling preparations for the event. The investigation is ongoing.
- What security measures does Microsoft 365 offer to prevent such attacks?
- Microsoft 365 includes multi-factor authentication, suspicious activity monitoring, and data encryption. However, protection effectiveness depends on user-configured security policies.
Dzen feed: /feed/dzen.xml · RSS: /feed.xml