ExfilSquad claims to have obtained 27 million records from 13 organizations through publicly accessible Microsoft Power Pages portals.
The group first appeared on July 26 with its own leak site on the dark web, initially claiming to have compromised 15 organizations without providing convincing evidence. Two days later, ExfilSquad released its first data samples, which were subsequently analyzed by researchers at Fortra Intelligence and Research Experts. Their assessment suggests that the incident likely involves genuine data exfiltration. However, it does not appear to be a full compromise of the affected organizations’ corporate networks, as is often seen in traditional ransomware attacks. Instead, the exposed data appears to be limited to individual SaaS applications.
The stolen information reportedly comes primarily from Microsoft Dynamics 365 CRM and ERP environments and is stored in a format consistent with typical exports from Microsoft’s Dataverse platform. Researchers found no evidence of system encryption, lateral movement within corporate networks, or an actual software vulnerability in Dynamics 365 itself.
Fortra considers publicly accessible Power Pages portals the most likely explanation. Organizations use these portals to interact with customers, employees, partners, and the public. While some data may intentionally be made available to unauthenticated visitors, other information is not meant to be publicly accessible. A misconfigured permission setting can therefore expose significantly more internal data than intended. As part of its investigation, Fortra identified more than 10,000 publicly accessible Power Pages instances.
Microsoft: Government Agencies, Schools, and Major Companies Affected
By August 7, ExfilSquad had published torrent files allegedly containing data from 13 organizations across an unusually broad range of sectors. The claimed victims include government agencies, educational institutions, financial services providers, aviation companies, and law enforcement organizations. Among the organizations named by the group are insurer Allstate, the City of Atlanta, District of Columbia Public Schools, the UK Department for Education, Frontier Airlines, the City of Houston, Newcastle University, and a UK police database.
Two organizations initially listed by the group were later removed, although the reason remains unclear. According to ExfilSquad’s own description, the alleged dataset involving the City of Houston alone contains around 6 million records, while the Atlanta dataset reportedly includes approximately 3 million. The exposed data categories allegedly include names, addresses, contact details, customer service records, employee and applicant information, and student data.
Recommended Immediate Actions
Organizations using Power Pages should first determine whether their portals allow anonymous users to access Dataverse data. This can include using the dedicated Power Pwn assessment module. If unintended exposure is identified, anonymous access to business data should be disabled immediately, while logs and portal configurations should be preserved for further investigation.
Affected organizations should then determine exactly which portals and datasets were exposed. Where necessary, they should rotate potentially affected credentials and API keys, document all Power Pages portals along with their designated owners and associated Dataverse environments, and move toward a strict Zero Trust model that requires authentication before any access to business data.
Organizations should also review connected services, including Power Automate, SharePoint, Power BI, payment systems, as well as custom-built connectors and service accounts.
(Editorial Team)