A security researcher discovered a vulnerability in the premium calculator website of Toyota Tsusho Insurance Broker India, which exposed Microsoft corporate cloud credentials and allowed access to a noreply email account containing sensitive customer information. The vulnerability was caused by a combination of security issues, including a client-side email sending mechanism, missing API authentication, and leaky API responses. The researcher reported the issue to the company, but it took over two months to fix the vulnerability, and the email account password was not changed until recently. The incident highlights the importance of proper security measures to protect customer data.