Microsoft Copilot Reportedly Able to Access Cached Data from Since-Private GitHub Repositories

February 26, 2025

Lasso Security revealed that Microsoft Copilot potentially exposed data from GitHub repositories, previously public but later set private or deleted. This exposure is believed to be due to Bing's caching system storing 'zombie data' from over 20,000 repositories, including sensitive information such as access keys, tokens, and internal packages. Microsoft classified the issue as low severity and applied only partial mitigations.

This incident highlights the importance of trustworthy AI and robust AI governance to prevent such occurrences. For those interested in shaping the future of safe and secure AI practices, consider joining HISPI Project Cerebellum TAIM (Govern) as we map, measure, and manage incidents like this one within our AI incident database.
JOIN US

Matched TAIM controls

Suggested mapping from embedding similarity (not a formal assessment). Browse all TAIM controls

Alleged deployer
microsoft
Alleged developer
microsoft
Alleged harmed parties
github-users, github-repositories, github

Source

Data from the AI Incident Database (AIID). Cite this incident: https://incidentdatabase.ai/cite/1174

Data source

Incident data is from the AI Incident Database (AIID).

When citing the database as a whole, please use:

McGregor, S. (2021) Preventing Repeated Real World AI Failures by Cataloging Incidents: The AI Incident Database. In Proceedings of the Thirty-Third Annual Conference on Innovative Applications of Artificial Intelligence (IAAI-21). Virtual Conference.

Pre-print on arXiv · Database snapshots & citation guide

We use weekly snapshots of the AIID for stable reference. For the official suggested citation of a specific incident, use the “Cite this incident” link on each incident page.