Microsoft AI Incidents: Entra ID Disruption and OpenAI Exploit

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

Microsoft resolved a DNS authentication issue in its Entra ID service that disrupted Azure access due to a recent DNS change. Meanwhile, hackers identified as Storm-2139 bypassed security in Azure OpenAI tools, enabling the creation of harmful AI-generated content, including non-consensual celebrity images, highlighting vulnerabilities in its AI infrastructure.[AI generated]

Why's our monitor labelling this an incident or hazard?

The event involves the malicious use of AI systems (Azure OpenAI) to produce harmful, non-consensual sexual images, which directly leads to harm to individuals and violations of rights. The hackers' actions represent misuse of AI capabilities causing real harm, qualifying this as an AI Incident. The involvement of AI systems in generating harmful content and the resulting harm to persons meet the criteria for an AI Incident rather than a hazard or complementary information.[AI generated]
AI principles
Robustness & digital securitySafetyPrivacy & data governanceRespect of human rightsAccountabilityTransparency & explainability

Industries
Media, social platforms, and marketingDigital securityIT infrastructure and hosting

Affected stakeholders
Other

Harm types
ReputationalPsychologicalHuman or fundamental rights

Business function:
ICT management and information securityResearch and development

AI system task:
Content generation


Articles about this incident or hazard