VYPR
breachPublished Aug 14, 2026· 1 source

ExfilSquad Confirms Data Theft from 13 Organizations, Exposing 382GB of Sensitive Information

The extortion group ExfilSquad has confirmed exfiltrating 382.64 GB of data from 13 organizations, with researchers verifying the claims and identifying misconfigured Microsoft Power Pages as a likely attack vector.

Researchers from Fortra Intelligence and Research Experts (FIRE) have confirmed that the extortion group ExfilSquad has successfully exfiltrated sensitive data from at least 13 organizations across various sectors, including government, education, financial services, and manufacturing. The group, which initially claimed to have compromised 15 entities, published data dumps for 13 victims via torrents on August 7th, stating these organizations failed to meet their demands. The total volume of leaked data is reported to be a staggering 382.64 GB, encompassing approximately 27 million records.

Among the confirmed victims are high-profile entities such as the City of Atlanta, the UK Department for Education, and the UK Police National Legal Database. The District of Columbia Public Schools (DCPS) was also targeted, with ExfilSquad releasing a censored version of the leak containing 60,000 records, including student names, dates of birth, and unique identifiers, while stating the original data was shredded. Notably, Zenith Bank Plc and Analog Devices, initially listed among the 15 victims, were not included in the public data dumps.

The FIRE team's analysis suggests that the breaches were most likely the result of unauthorized access to Microsoft D365 CRM and ERP instances. The leading theory for the initial attack vector points to misconfigured Microsoft Power Page portals, which inadvertently allowed for public read access to sensitive data. This misconfiguration is a known issue within the Power Pages platform, where assigning the Anonymous Users web role to a table permission can expose data to any visitor.

Fortra researchers noted that the leaked data formations were consistent with Microsoft Dataverse exports, strongly indicating that unauthorized read access was the primary method of exfiltration. Threat actors likely identified vulnerable instances by actively scanning for misconfigured Power Portals or employing other enumeration techniques. The scale of the breach, affecting 13 specific victims rather than a widespread vulnerability, suggests that a core D365 flaw was not the source.

Microsoft's own documentation advises against using the Anonymous Users role on publicly exposed sites, highlighting the potential for data exposure. The Power Pages platform can be accessed via an API, and automated scanning for exposed sites is a recognized technique. Fortra's research identified over 10,000 potentially publicly accessible Power Pages instances, underscoring the broad attack surface.

ExfilSquad's emergence on July 26th marks another significant player in the data extortion landscape. The group's tactic of publishing data via torrents after failed negotiations is a common, albeit aggressive, strategy to pressure victims into paying ransoms. The diverse range of targeted sectors highlights the indiscriminate nature of these attacks and the broad impact on public and private institutions.

The confirmation of this widespread data exfiltration serves as a stark reminder for organizations to rigorously audit their cloud configurations, particularly for platforms like Microsoft Power Pages. Proactive security measures, including regular access control reviews and adherence to vendor security best practices, are crucial to prevent such unauthorized data access and subsequent extortion attempts.

Synthesized by Vypr AI