ANY.RUN Research Uncovers Major Data Leak Caused by Microsoft Defender XDR False Positive
ANY.RUN researchers have uncovered a significant data leak triggered by a false positive detection in Microsoft Defender XDR. The security platform mistakenly flagged harmless files as malicious, leading to their automatic submission to ANY.RUN’s public sandbox for analysis. Consequently, more than 1,700 sensitive documents were uploaded and publicly indexed.
The breach, involving corporate data from hundreds of companies, highlights the serious risks associated with misclassification in threat detection systems and the unintended fallout from user actions in response to such errors.
The incident unfolded when Microsoft Defender XDR — a widely trusted advanced threat protection platform — erroneously flagged legitimate Adobe Acrobat Cloud links, specifically URLs beginning with acrobat[.]adobe[.]com/id/urn:aaid:sc:, as malicious.
According to an ANY.RUN report shared with Cyber Security News, this error triggered a sudden wave of Adobe Acrobat Cloud links being uploaded to their sandbox environment.
🚨 Important: A false positive from Microsoft Defender XDR resulted in over 1,700 sensitive documents being publicly shared via #ANYRUN.
Just a few hours ago, we noticed an unexpected surge of Adobe Acrobat Cloud links uploaded to ANYRUN’s sandbox.
Our investigation revealed… [pic.twitter.com/v66AHFMsJN — ANY.RUN (@anyrun_app) April 24, 2025]
Many of the affected uploads were initiated by users on ANY.RUN’s free plan, which defaults to a public sharing mode—unintentionally exposing confidential corporate data to the public.
ANY.RUN’s investigation confirmed that the false positive led to the exposure of more than 1,700 Adobe files containing sensitive information, impacting hundreds of organizations.

ANY.RUN Traces Massive Data Exposure to Microsoft Defender XDR False Positive
Earlier today, ANY.RUN detected an unusual spike in uploads containing Adobe Acrobat Cloud links. Upon investigation, the team traced the cause to a false positive in Microsoft Defender XDR, which had mistakenly flagged a legitimate URL — acrobat[.]adobe[.]com/id/urn:aaid:sc: — as malicious. ANY.RUN shared its findings with Cyber Security News.
The exposed documents contained a broad range of sensitive corporate information, raising significant concerns about potential data breaches and the misuse of proprietary data.
In response, ANY.RUN quickly acted to limit the damage by converting all related analyses to private mode, preventing further public access. However, the company noted that some users continued uploading confidential documents publicly, worsening the exposure.
“We observed a sudden inflow of Adobe Acrobat Cloud links being uploaded to ANY.RUN’s sandbox just a few hours ago,” the team stated.
“To prevent further leaks, we’re moving all these analyses to private mode. However, users are still uploading sensitive documents publicly. For work-related tasks, always use a commercial license to ensure privacy and compliance.”
As reported by PUPUWEB on April 24, 2025, incidents like this highlight how false positives can erode trust in detection systems and introduce major security risks if not quickly addressed.
In this case, the Microsoft Defender XDR misclassification prompted users to take actions that inadvertently exposed confidential data—underscoring the critical need for precise threat detection to avoid cascading effects.
The report also urged users who encounter false positives in Microsoft Defender XDR to promptly submit them to Microsoft for analysis and resolution, a step that could help prevent future incidents.
This data leak adds to growing concerns about vulnerabilities in cloud-based environments. Just a day earlier, on April 23, cybersecurity expert Florian Roth (@cyb3rops) posted on X about attackers increasingly shifting focus from traditional endpoints to cloud platforms like Microsoft 365, Google Workspace, and AWS.
Roth noted that cloud environments often lack comprehensive logging and detection capabilities, leaving critical blind spots that attackers can exploit.
The ANY.RUN incident starkly illustrates how security tool errors in cloud environments can magnify risks, leading to widespread unintended data exposure.
The event has sparked renewed calls for organizations to strengthen their data handling practices in cloud settings and to ensure that cybersecurity tools maintain a careful balance between sensitivity and accuracy to minimize false positives.
As the cybersecurity landscape continues to evolve, incidents like this emphasize the need for ongoing vigilance, accurate threat detection, and robust user education to safeguard sensitive information.




