Organization
SOCRadar
Threat-intelligence company whose researcher publicly disclosed the BMW misconfigured cloud bucket finding.
What to know first
- IdentitySOCRadar, CompanyHigh confidence
Basic information
- Display nameSOCRadarHigh confidence
- Directory categoryCompanyHigh confidence
- AliasesSOCRadar Extended Threat IntelligenceMedium confidence
- Last updatedAug 28, 2026High confidence
Locations
- Geography scopeUnited States / United States / TurkeyHigh confidence
- Other infrastructure servicesUnited States / United States / TurkeyMedium confidence
Other network resources
- Service platformSOCRadar United States Other infrastructure services · United States / United States / TurkeyHigh confidence
Source basis
- TechCrunch report on BMW exposed Azure storage bucketTechCrunch reported on February 14, 2024 that a misconfigured Microsoft Azure-hosted storage bucket in BMW's development environment exposed private keys, internal cloud details and production/development database credentials; BMW confirmed the affected bucket, said no customer or personal data was impacted and said the issue was fixed at the beginning of 2024.High confidence
- SOCRadar disclosure on BMW misconfigured cloud bucketSOCRadar said researcher Can Yoleri found the BMW cloud bucket during a December 18, 2023 scan, described it as a Microsoft Azure-hosted development storage bucket set to public access, and identified exposed private keys, Azure container access information, other cloud-service details and development/production database connection information.High confidence
- BMW Group official company profileBMW Group's official company profile supports the identity and scale context for Bayerische Motoren Werke AG, including its global sales network, worldwide production sites and workforce.High confidence
- BMW Group official data ecosystem pageBMW Group's data ecosystem page describes data protection, customer control, connected-vehicle data and responsible data handling as strategic BMW control surfaces, which frames why cloud-secret exposure in automotive software operations matters even where the incident did not expose customer data.High confidence
- Microsoft Learn on remediating anonymous Azure Blob accessMicrosoft Learn states that Azure Storage supports optional anonymous read access for containers and blobs, recommends disabling anonymous access for storage accounts, and says setting AllowBlobPublicAccess to false requires authorization for all blob-data requests.High confidence
