Skip to main content
Emerging ThreatsData Breaches

ExfilSquad Breaches 13 Organizations Via Misconfigured Microsoft Power Pages

Modern office equipment sits amidst scattered papers outside a brightly-lit office building or data center.

“The full archive “[victim]_exfilsquad” was made available for download and the total data was reported to be 382.64 GB and 27 million records across the 13 victims.”

Scope and scale of the ExfilSquad dumps

New analysis by Fortra Intelligence and Research Experts (FIRE) confirms that the ExfilSquad data-extortion group has published authentic data from at least 13 victims across government, education, financial services and manufacturing. The group, which first emerged on July 26, claimed to have exfiltrated data from 15 organizations; on August 7 it published data dumps for 13 victims via torrents. FIRE’s review of the publicly posted samples found the criminals’ claim that they had access to sensitive data to be correct.

Fortra reported that the published archive used the “[victim]_exfilsquad” naming convention and that the combined archive amounted to 382.64 GB and 27 million records across the 13 victims. Two organizations listed in the original 15 — Zenith Bank Plc and Analog Devices — were not present in the published set, Fortra noted.

Confirmed victims and a notable redaction

The victims named in the published dumps include the City of Atlanta (atlantaga.gov), the UK Department for Education (education.gov.uk) and the UK Police National Legal Database. District of Columbia Public Schools (DCPS) also appeared on the attackers’ list. In DCPS’s case the attackers posted a note saying: “We are not going to dox a bunch of school children, but we are going to expose how incompetent DCPS is at keeping children as young as six's information safe. Thus, we are releasing a censored version of the leak and have shredded the original entirely from our servers.”

FIRE reported that the DCPS publication included 60,000 records containing student names, dates of birth and unique student identifiers, among other personally identifiable information (PII), in a censored form released by the attackers.

Fortra FIRE’s technical conclusions on access and data formation

FIRE’s analysis tied the leaked data to unauthorized reads of Microsoft D365 CRM and ERP instances. The researchers wrote: “The leading theory on the initial attack vector that enabled exfiltration is misconfigured Microsoft Power Page portals that allowed for public read access.”

Fortra observed that the leaked data formations were consistent with Microsoft Dataverse exports, which suggested the attackers likely achieved unauthorized read access to Dataverse data during the incidents. The firm also argued that because the breach impacted just 15 victims rather than tens of thousands, it was unlikely a vulnerability in D365 itself was the root cause.

Microsoft Power Pages misconfiguration and automated discovery

Power Pages is a software-as-a-service platform for creating external-facing business websites. FIRE highlighted a known configuration issue: when the Anonymous Users web role is assigned to a table permission, the table’s data can be read by anyone visiting the site. Power Pages content, the researchers noted, can be accessed programmatically via an API endpoint pattern such as https://<portal>/_api/*.

Microsoft documentation explicitly advises against assigning the Anonymous Users role on publicly exposed sites; Fortra referenced this guidance at https://learn.microsoft.com/en-us/power-pages/security/assign-table-permissions. The FIRE team said automated scanning for exposed Power Pages instances is a known technique and that in their research they were able to identify over 10,000 potential Power Pages sites accessible to the public — a surface that attackers could crawl to find misconfigurations.

What this means for security teams, regulators, and education officials

  • Security teams and technologists: the Fortra analysis points to configuration hygiene as the primary control failure — misassigned web roles and exposed APIs rather than an exploit of D365. Teams should review Power Pages table permissions and audit any use of the Anonymous Users web role on externally accessible portals.
  • Regulators and procurement leaders: the incident highlights third-party SaaS configuration as an outsized source of exposure. Fortra’s finding that the incident affected a small, discrete number of victims rather than a platform-wide flaw may shape regulatory attention toward contractual controls and configuration audits.
  • Education and local government officials: the DCPS disclosure underscores how student PII can appear in extortion dumps even when attackers claim to redact sensitive children’s data. Officials responsible for externally facing portals and CRM/ERP exports will need to verify that Dataverse exports and site roles are not exposing records unintentionally.

FIRE’s report ties a sizable, multi-sector leak to misconfigured Microsoft Power Pages portals and publicly accessible Dataverse exports, rather than to a platform-wide vulnerability. The published archive and the attackers’ own notes make clear that extortion groups are actively crawling for misconfigurations and publishing large data sets when their demands are not met — in this case resulting in a 382.64 GB, 27 million-record release across 13 victims.

Read the original Fortra-based report: https://www.infosecurity-magazine.com/news/exfilsquads-13-organizations/