{"id":1491,"date":"2026-01-15T12:43:45","date_gmt":"2026-01-15T11:43:45","guid":{"rendered":"https:\/\/gfdde.de\/?p=1491"},"modified":"2026-05-04T11:40:21","modified_gmt":"2026-05-04T09:40:21","slug":"wie-sicher-sind-verschluesselte-daten-wenn-der-schluessel-in-der-cloud-liegt","status":"publish","type":"post","link":"https:\/\/gfdde.de\/en\/wie-sicher-sind-verschluesselte-daten-wenn-der-schluessel-in-der-cloud-liegt\/","title":{"rendered":"How secure is encrypted data if the key is stored in the cloud?"},"content":{"rendered":"<div data-elementor-type=\"wp-post\" data-elementor-id=\"1491\" class=\"elementor elementor-1491\" data-elementor-post-type=\"post\">\n\t\t\t\t<div class=\"elementor-element elementor-element-26f71f3a e-con-full e-flex e-con e-parent\" data-id=\"26f71f3a\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t<div class=\"elementor-element elementor-element-aa02516 elementor-align-center elementor-widget elementor-widget-post-info\" data-id=\"aa02516\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"post-info.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<ul class=\"elementor-inline-items elementor-icon-list-items elementor-post-info\">\n\t\t\t\t\t\t\t\t<li class=\"elementor-icon-list-item elementor-repeater-item-7f530f1 elementor-inline-item\" itemprop=\"datePublished\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text elementor-post-info__item elementor-post-info__item--type-date\">\n\t\t\t\t\t\t\t\t\t\t<time>15.01.2026<\/time>\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t<\/ul>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-15c7725 e-con-full e-flex e-con e-child\" data-id=\"15c7725\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-4b053450 elementor-widget__width-initial elementor-widget-tablet__width-inherit elementor-widget elementor-widget-heading\" data-id=\"4b053450\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">How secure is encrypted data if the key is stored in the cloud?<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-562ba32b elementor-widget__width-initial elementor-widget-tablet__width-inherit elementor-widget elementor-widget-text-editor\" data-id=\"562ba32b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\tA report published by Forbes in January 2026 provides the first public evidence that Microsoft has handed over BitLocker recovery keys to the FBI. This was made technically possible by the default configuration of modern Windows versions, which automatically upload recovery keys to the Microsoft cloud. For companies in the DACH region, this results in an immediate need for review: key ownership as a core element of technical safeguards under Article 32 GDPR must be reassessed. The case illustrates that cloud-bound encryption solutions without independent key management do not provide sufficient protection.\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-354238d1 elementor-widget__width-inherit elementor-invisible elementor-widget elementor-widget-image\" data-id=\"354238d1\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;_animation&quot;:&quot;fadeInUp&quot;}\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img fetchpriority=\"high\" decoding=\"async\" width=\"800\" height=\"450\" src=\"https:\/\/gfdde.de\/wp-content\/uploads\/2026\/04\/jose-ramos-BWCgQw25XUE-unsplash_bearb-1024x576.webp\" class=\"attachment-large size-large wp-image-1504\" alt=\"\" srcset=\"https:\/\/gfdde.de\/wp-content\/uploads\/2026\/04\/jose-ramos-BWCgQw25XUE-unsplash_bearb-1024x576.webp 1024w, https:\/\/gfdde.de\/wp-content\/uploads\/2026\/04\/jose-ramos-BWCgQw25XUE-unsplash_bearb-300x169.webp 300w, https:\/\/gfdde.de\/wp-content\/uploads\/2026\/04\/jose-ramos-BWCgQw25XUE-unsplash_bearb-768x432.webp 768w, https:\/\/gfdde.de\/wp-content\/uploads\/2026\/04\/jose-ramos-BWCgQw25XUE-unsplash_bearb-1536x864.webp 1536w, https:\/\/gfdde.de\/wp-content\/uploads\/2026\/04\/jose-ramos-BWCgQw25XUE-unsplash_bearb-2048x1153.webp 2048w, https:\/\/gfdde.de\/wp-content\/uploads\/2026\/04\/jose-ramos-BWCgQw25XUE-unsplash_bearb-18x10.webp 18w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-42937699 e-con-full e-flex e-con e-child\" data-id=\"42937699\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t<div class=\"elementor-element elementor-element-7f8b6c34 e-con-full e-flex e-con e-child\" data-id=\"7f8b6c34\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-d1c7786 elementor-widget__width-initial elementor-widget elementor-widget-text-editor\" data-id=\"d1c7786\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<h5>Background<\/h5>\nBitLocker is Microsoft\u2019s native full-disk encryption mechanism for Windows drives and is enabled by default on modern devices. According to reports by Forbes, TechCrunch, and Tom\u2019s Hardware, Microsoft provided the FBI with BitLocker recovery keys for three seized laptops in the spring of 2025 as part of a law enforcement request. Microsoft confirmed to Forbes that it receives an average of around 20 such requests per year.<p><p>\nThe technical core of the issue is that Windows 11 requires a Microsoft account by default during setup, which means BitLocker keys are automatically linked to the user\u2019s online identity and stored in the Microsoft cloud. In the Home edition, this cloud storage is effectively mandatory. Even in Enterprise and Education editions, cloud storage may be active depending on Group Policy configuration and is promoted by Microsoft as the recommended approach.<p><p>\nBy comparison, Apple stores FileVault keys via iCloud Keychain using end-to-end encryption, meaning Apple itself has no access and therefore cannot hand over keys even under legal compulsion. Microsoft, by contrast, has structural access to these keys and provides them when legally required.\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-6ca6332f elementor-widget__width-initial elementor-widget elementor-widget-text-editor\" data-id=\"6ca6332f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<h5>Legal and Data Protection Assessment <\/h5>\nArticle 32 GDPR requires controllers to implement appropriate technical measures to secure personal data, including, explicitly, encryption. The decisive factor, however, is not merely the use of encryption, but who holds the key ownership.<p><p>\nIf BitLocker keys are stored in the Microsoft cloud, the factual control over the encrypted data no longer lies exclusively with the organization. As a result, the protective effect of encryption against third parties \u2013 including U.S. authorities based on the CLOUD Act \u2013 is limited. This directly affects the assessment of technical safeguards under Article 32 GDPR, the execution of Transfer Impact Assessments (TIA) when using Microsoft cloud products in the context of international data transfers, and the records of processing activities as well as the outcome of the Data Protection Impact Assessment (DPIA) under Article 35 GDPR.<p><p>\nIn addition, it must be considered that the U.S. CLOUD Act enables U.S. authorities, under certain conditions, to access data managed by U.S. companies \u2013 regardless of where the data is stored. As a U.S.-based corporation, Microsoft is also subject to this jurisdiction.\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-21be7c23 elementor-widget__width-initial elementor-widget elementor-widget-text-editor\" data-id=\"21be7c23\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<h5>Risk Assessment for Organizations<\/h5>\nThe risk is multidimensional:\n<ul><li>Government access: U.S. law enforcement authorities (and, in the future, potentially other law enforcement agencies with corresponding mutual legal assistance frameworks) may access device data via Microsoft without needing to technically break encryption.<\/li>\n<li>Data breach risk: Compromises of Microsoft cloud infrastructure (historically documented on multiple occasions) could expose recovery keys to third parties.<\/li>\n<li>Compliance risk: Organizations that have documented BitLocker as their sole security measure under Article 32 GDPR, without independently controlling key management, risk an incomplete security controls framework.<\/li>\n<li>Reputational risk: In the event of a data protection incident involving cloud-stored keys, organizations may face difficult-to-explain gaps in their security concept.<\/li><\/ul><p><p>\nCompanies are particularly exposed if they use Windows Home editions, operate devices without dedicated Group Policy configuration, rely on managed device environments with default settings, or list BitLocker in their DPIA or technical and organizational measures (TOM) catalogue as an effective security measure without documenting the key storage location.\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-568d1356 e-con-full e-flex e-con e-child\" data-id=\"568d1356\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-32d5384b elementor-widget__width-initial elementor-widget elementor-widget-text-editor\" data-id=\"32d5384b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<h5>Recommendations for Action<\/h5>\n<ul>\n \t<li>Inventory: Check whether BitLocker keys are stored in Microsoft cloud accounts and on which devices this applies. This can be verified via the Microsoft account portal as well as through Active Directory \/ Azure AD.<\/li>\n \t<li>Establish key ownership: Configure BitLocker via Group Policy so that keys are stored exclusively locally (on-premises Active Directory or an internal key management system). If necessary, delete keys already stored in the cloud.<\/li>\n \t<li>Update TOM documentation: Add the specific key storage location and access controls to your records of technical and organizational measures.<\/li>\n \t<li>Review TIA: If Microsoft cloud services are in use, verify whether the existing Transfer Impact Assessment adequately addresses the issue of cloud-stored encryption keys and the implications of the CLOUD Act.<\/li>\n \t<li>Evaluate alternative encryption solutions: For highly sensitive areas, it is recommended to assess solutions with a proven zero-knowledge architecture or fully independent key management.\n<\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2619048 elementor-widget__width-initial elementor-widget elementor-widget-text-editor\" data-id=\"2619048\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<h5>Need for consulting?<\/h5>\nGfDDE \u2013 Gesellschaft f\u00fcr Datenschutz und Datensicherheit \u2013 in Europa GmbH supports you in the assessment of cloud-bound encryption solutions in the GDPR context \u2013 practical and professionally grounded. \t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2f09e79c elementor-align-center elementor-mobile-align-center elementor-tablet-align-center elementor-widget__width-inherit elementor-invisible elementor-widget elementor-widget-button\" data-id=\"2f09e79c\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;_animation&quot;:&quot;fadeInUp&quot;}\" data-widget_type=\"button.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-button-wrapper\">\n\t\t\t\t\t<a class=\"elementor-button elementor-button-link elementor-size-sm elementor-animation-grow\" href=\"https:\/\/gfdde.de\/en\/?preview_id=57&#038;preview_nonce=5ba13b97f0&#038;preview=true#Kontakt\">\n\t\t\t\t\t\t<span class=\"elementor-button-content-wrapper\">\n\t\t\t\t\t\t\t\t\t<span class=\"elementor-button-text\">Get in Touch now<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-744c4af1 elementor-widget__width-initial elementor-widget elementor-widget-text-editor\" data-id=\"744c4af1\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<h5>Sources<\/h5>\nForbes \/ Thomas Brewster (22 January 2026): Microsoft Gave FBI Keys To Unlock BitLocker Encrypted Data\n<br><br>\nTechCrunch (23 January 2026): Microsoft gave FBI a set of BitLocker encryption keys to unlock suspects\u2019 laptops\n<br><br>\nTom\u2019s Hardware (24 January 2026): Microsoft gave customers\u2019 BitLocker encryption keys to the FBI\n<br><br>\nTechRepublic (26 January 2026): Microsoft Shared BitLocker Keys With FBI, Raising Privacy Fears\n<br><br>\nSchneier on Security (3 February 2026): Microsoft is Giving the FBI BitLocker Keys\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-2dad023c e-con-full e-flex e-con e-parent\" data-id=\"2dad023c\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-1bcc04ee elementor-widget elementor-widget-heading\" data-id=\"1bcc04ee\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">More news<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-59ea37cc elementor-posts__hover-none elementor-grid-3 elementor-grid-tablet-2 elementor-grid-mobile-1 elementor-posts--thumbnail-top elementor-widget elementor-widget-posts\" data-id=\"59ea37cc\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;cards_row_gap&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:80,&quot;sizes&quot;:[]},&quot;cards_row_gap_tablet&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:71,&quot;sizes&quot;:[]},&quot;cards_row_gap_mobile&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:30,&quot;sizes&quot;:[]},&quot;cards_columns&quot;:&quot;3&quot;,&quot;cards_columns_tablet&quot;:&quot;2&quot;,&quot;cards_columns_mobile&quot;:&quot;1&quot;}\" data-widget_type=\"posts.cards\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-posts-container elementor-posts elementor-posts--skin-cards elementor-grid\" role=\"list\">\n\t\t\t\t<article class=\"elementor-post elementor-grid-item post-1580 post type-post status-publish format-standard has-post-thumbnail hentry category-allgemein\" role=\"listitem\">\n\t\t\t<div class=\"elementor-post__card\">\n\t\t\t\t<a class=\"elementor-post__thumbnail__link\" href=\"https:\/\/gfdde.de\/en\/us-supreme-court-kippt-ftc-unabhaengigkeit\/\" tabindex=\"-1\" target=\"_blank\"><div class=\"elementor-post__thumbnail\"><img decoding=\"async\" width=\"2000\" height=\"1334\" src=\"https:\/\/gfdde.de\/wp-content\/uploads\/2026\/07\/tim-mossholder-3Xl3lI5gjqg-unsplash_bearb.webp\" class=\"attachment-full size-full wp-image-1579\" alt=\"\" srcset=\"https:\/\/gfdde.de\/wp-content\/uploads\/2026\/07\/tim-mossholder-3Xl3lI5gjqg-unsplash_bearb.webp 2000w, https:\/\/gfdde.de\/wp-content\/uploads\/2026\/07\/tim-mossholder-3Xl3lI5gjqg-unsplash_bearb-300x200.webp 300w, https:\/\/gfdde.de\/wp-content\/uploads\/2026\/07\/tim-mossholder-3Xl3lI5gjqg-unsplash_bearb-1024x683.webp 1024w, https:\/\/gfdde.de\/wp-content\/uploads\/2026\/07\/tim-mossholder-3Xl3lI5gjqg-unsplash_bearb-768x512.webp 768w, https:\/\/gfdde.de\/wp-content\/uploads\/2026\/07\/tim-mossholder-3Xl3lI5gjqg-unsplash_bearb-1536x1025.webp 1536w, https:\/\/gfdde.de\/wp-content\/uploads\/2026\/07\/tim-mossholder-3Xl3lI5gjqg-unsplash_bearb-18x12.webp 18w\" sizes=\"(max-width: 2000px) 100vw, 2000px\" \/><\/div><\/a>\n\t\t\t\t<div class=\"elementor-post__text\">\n\t\t\t\t<h4 class=\"elementor-post__title\">\n\t\t\t<a href=\"https:\/\/gfdde.de\/en\/us-supreme-court-kippt-ftc-unabhaengigkeit\/\" target=\"&quot;_blank&quot;\">\n\t\t\t\tUS Supreme Court kippt FTC-Unabh\u00e4ngigkeit: Rechtsgrundlage des EU-US Data Privacy Framework weiter ersch\u00fcttert\t\t\t<\/a>\n\t\t<\/h4>\n\t\t\t\t<div class=\"elementor-post__excerpt\">\n\t\t\t<p>US Supreme Court kippt FTC-Unabh\u00e4ngigkeit: Rechtsgrundlage des EU-US Data Privacy Framework weiter ersch\u00fcttert Der US Supreme Court hat am 29. Juni 2026 im Verfahren Trump v. Slaughter mit 6:3-Mehrheit entschieden, dass die gesetzlichen Abberufungsschutzregelungen f\u00fcr<\/p>\n\t\t<\/div>\n\t\t\n\t\t<a class=\"elementor-post__read-more\" href=\"https:\/\/gfdde.de\/en\/us-supreme-court-kippt-ftc-unabhaengigkeit\/\" aria-label=\"Read more about US Supreme Court kippt FTC-Unabh\u00e4ngigkeit: Rechtsgrundlage des EU-US Data Privacy Framework weiter ersch\u00fcttert\" tabindex=\"-1\" target=\"_blank\">\n\t\t\tRead more\u2026\t\t<\/a>\n\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/article>\n\t\t\t\t<article class=\"elementor-post elementor-grid-item post-1496 post type-post status-publish format-standard has-post-thumbnail hentry category-allgemein\" role=\"listitem\">\n\t\t\t<div class=\"elementor-post__card\">\n\t\t\t\t<a class=\"elementor-post__thumbnail__link\" href=\"https:\/\/gfdde.de\/en\/cloud-act-fisa-und-co-wann-eu-rechenzentren-europaeischen-daten-keinen-schutz-bieten\/\" tabindex=\"-1\" target=\"_blank\"><div class=\"elementor-post__thumbnail\"><img decoding=\"async\" width=\"2560\" height=\"1696\" src=\"https:\/\/gfdde.de\/wp-content\/uploads\/2026\/04\/domaintechnik-ledl-net-VHmBX7FnXw0-unsplash_bearb-scaled.webp\" class=\"attachment-full size-full wp-image-1506\" alt=\"\" srcset=\"https:\/\/gfdde.de\/wp-content\/uploads\/2026\/04\/domaintechnik-ledl-net-VHmBX7FnXw0-unsplash_bearb-scaled.webp 2560w, https:\/\/gfdde.de\/wp-content\/uploads\/2026\/04\/domaintechnik-ledl-net-VHmBX7FnXw0-unsplash_bearb-300x199.webp 300w, https:\/\/gfdde.de\/wp-content\/uploads\/2026\/04\/domaintechnik-ledl-net-VHmBX7FnXw0-unsplash_bearb-1024x678.webp 1024w, https:\/\/gfdde.de\/wp-content\/uploads\/2026\/04\/domaintechnik-ledl-net-VHmBX7FnXw0-unsplash_bearb-768x509.webp 768w, https:\/\/gfdde.de\/wp-content\/uploads\/2026\/04\/domaintechnik-ledl-net-VHmBX7FnXw0-unsplash_bearb-1536x1017.webp 1536w, https:\/\/gfdde.de\/wp-content\/uploads\/2026\/04\/domaintechnik-ledl-net-VHmBX7FnXw0-unsplash_bearb-2048x1356.webp 2048w, https:\/\/gfdde.de\/wp-content\/uploads\/2026\/04\/domaintechnik-ledl-net-VHmBX7FnXw0-unsplash_bearb-18x12.webp 18w\" sizes=\"(max-width: 2560px) 100vw, 2560px\" \/><\/div><\/a>\n\t\t\t\t<div class=\"elementor-post__text\">\n\t\t\t\t<h4 class=\"elementor-post__title\">\n\t\t\t<a href=\"https:\/\/gfdde.de\/en\/cloud-act-fisa-und-co-wann-eu-rechenzentren-europaeischen-daten-keinen-schutz-bieten\/\" target=\"&quot;_blank&quot;\">\n\t\t\t\tCLOUD Act, FISA and Co.: When EU Data Centers Fail to Protect European Data\t\t\t<\/a>\n\t\t<\/h4>\n\t\t\t\t<div class=\"elementor-post__excerpt\">\n\t\t\t<p>Storing corporate data in European data centers operated by U.S. providers does not rule out access by U.S. authorities. A legal opinion by the University of Cologne, commissioned by the German Federal Ministry of the Interior and published in December 2025, confirms that U.S. authorities have extensive access to cloud data stored in Europe.<\/p>\n\t\t<\/div>\n\t\t\n\t\t<a class=\"elementor-post__read-more\" href=\"https:\/\/gfdde.de\/en\/cloud-act-fisa-und-co-wann-eu-rechenzentren-europaeischen-daten-keinen-schutz-bieten\/\" aria-label=\"Read more about CLOUD Act, FISA und Co.: Wann EU-Rechenzentren europ\u00e4ischen Daten keinen Schutz bieten\" tabindex=\"-1\" target=\"_blank\">\n\t\t\tRead more\u2026\t\t<\/a>\n\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/article>\n\t\t\t\t<article class=\"elementor-post elementor-grid-item post-1474 post type-post status-publish format-standard has-post-thumbnail hentry category-allgemein\" role=\"listitem\">\n\t\t\t<div class=\"elementor-post__card\">\n\t\t\t\t<a class=\"elementor-post__thumbnail__link\" href=\"https:\/\/gfdde.de\/en\/phishing-ueber-echte-microsoft-adresse-power-bi-missbrauch-und-dsgvo-pflichten-fuer-unternehmen\/\" tabindex=\"-1\" target=\"_blank\"><div class=\"elementor-post__thumbnail\"><img loading=\"lazy\" decoding=\"async\" width=\"2560\" height=\"1707\" src=\"https:\/\/gfdde.de\/wp-content\/uploads\/2026\/04\/le-vu-vSlCNmZdjHQ-unsplash_bearb-scaled.webp\" class=\"attachment-full size-full wp-image-1505\" alt=\"\" srcset=\"https:\/\/gfdde.de\/wp-content\/uploads\/2026\/04\/le-vu-vSlCNmZdjHQ-unsplash_bearb-scaled.webp 2560w, https:\/\/gfdde.de\/wp-content\/uploads\/2026\/04\/le-vu-vSlCNmZdjHQ-unsplash_bearb-300x200.webp 300w, https:\/\/gfdde.de\/wp-content\/uploads\/2026\/04\/le-vu-vSlCNmZdjHQ-unsplash_bearb-1024x683.webp 1024w, https:\/\/gfdde.de\/wp-content\/uploads\/2026\/04\/le-vu-vSlCNmZdjHQ-unsplash_bearb-768x512.webp 768w, https:\/\/gfdde.de\/wp-content\/uploads\/2026\/04\/le-vu-vSlCNmZdjHQ-unsplash_bearb-1536x1024.webp 1536w, https:\/\/gfdde.de\/wp-content\/uploads\/2026\/04\/le-vu-vSlCNmZdjHQ-unsplash_bearb-2048x1365.webp 2048w, https:\/\/gfdde.de\/wp-content\/uploads\/2026\/04\/le-vu-vSlCNmZdjHQ-unsplash_bearb-18x12.webp 18w\" sizes=\"(max-width: 2560px) 100vw, 2560px\" \/><\/div><\/a>\n\t\t\t\t<div class=\"elementor-post__text\">\n\t\t\t\t<h4 class=\"elementor-post__title\">\n\t\t\t<a href=\"https:\/\/gfdde.de\/en\/phishing-ueber-echte-microsoft-adresse-power-bi-missbrauch-und-dsgvo-pflichten-fuer-unternehmen\/\" target=\"&quot;_blank&quot;\">\n\t\t\t\tPhishing via a legitimate Microsoft address: Power BI abuse and GDPR obligations for companies\t\t\t<\/a>\n\t\t<\/h4>\n\t\t\t\t<div class=\"elementor-post__excerpt\">\n\t\t\t<p>Since January 2026, a sophisticated phishing campaign has been active in which attackers send deceptive emails using the legitimate Microsoft sender address no-reply-powerbi@microsoft.com\n. This is technically possible due to a legitimate feature of Microsoft Power BI: when creating a dashboard, any external email address can be added as a subscriber, and the content of the automatically sent notification can be freely configured.<\/p>\n\t\t<\/div>\n\t\t\n\t\t<a class=\"elementor-post__read-more\" href=\"https:\/\/gfdde.de\/en\/phishing-ueber-echte-microsoft-adresse-power-bi-missbrauch-und-dsgvo-pflichten-fuer-unternehmen\/\" aria-label=\"Read more about Phishing \u00fcber echte Microsoft-Adresse: Power-BI-Missbrauch und DSGVO-Pflichten f\u00fcr Unternehmen\" tabindex=\"-1\" target=\"_blank\">\n\t\t\tRead more\u2026\t\t<\/a>\n\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/article>\n\t\t\t\t<\/div>\n\t\t\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>","protected":false},"excerpt":{"rendered":"<p>A report published by Forbes in January 2026 provides the first public evidence that Microsoft has handed over BitLocker recovery keys to the FBI. This was made technically possible by the default configuration of modern Windows versions, which automatically upload recovery keys to the Microsoft cloud. For companies in the DACH region, this results in an immediate need for review:<\/p>","protected":false},"author":2,"featured_media":1504,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-1491","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-allgemein"],"_links":{"self":[{"href":"https:\/\/gfdde.de\/en\/wp-json\/wp\/v2\/posts\/1491","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/gfdde.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/gfdde.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/gfdde.de\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/gfdde.de\/en\/wp-json\/wp\/v2\/comments?post=1491"}],"version-history":[{"count":11,"href":"https:\/\/gfdde.de\/en\/wp-json\/wp\/v2\/posts\/1491\/revisions"}],"predecessor-version":[{"id":1566,"href":"https:\/\/gfdde.de\/en\/wp-json\/wp\/v2\/posts\/1491\/revisions\/1566"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/gfdde.de\/en\/wp-json\/wp\/v2\/media\/1504"}],"wp:attachment":[{"href":"https:\/\/gfdde.de\/en\/wp-json\/wp\/v2\/media?parent=1491"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/gfdde.de\/en\/wp-json\/wp\/v2\/categories?post=1491"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/gfdde.de\/en\/wp-json\/wp\/v2\/tags?post=1491"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}