A newly identified data extortion group called ExfilSquad claims to have obtained more than 27 million records belonging to organizations across several industries. Unlike conventional ransomware operations, early analysis suggests the campaign may rely on improperly configured Microsoft Power Pages portals rather than exploiting a vulnerability in Microsoft Dynamics 365.

 

 

ExfilSquad emerged publicly on July 26, 2026, when it launched a dark web leak site and initially claimed 15 victims. The group subsequently published samples and, after an alleged August 5 payment deadline passed, began releasing large quantities of purportedly stolen information.

Researchers at Fortra examined available samples and concluded that they appeared consistent with a genuine data breach. However, the evidence did not indicate complete compromises of the organizations’ internal networks. Instead, the exposed information appeared limited primarily to software-as-a-service environments.

The structure of the records pointed toward Microsoft Dynamics 365 CRM and ERP environments, particularly information stored in Microsoft Dataverse. Researchers found no evidence of ransomware encryption, lateral movement across victim networks, or exploitation of a vulnerability within Dynamics 365 itself.

The leading explanation instead involves Microsoft Power Pages, a service organizations can use to create external websites connected to business information held in Dataverse. Incorrectly configured permissions can potentially make records available to visitors who have not authenticated.

Microsoft’s own documentation warns administrators to carefully control table permissions granted to anonymous users. Fortra identified more than 10,000 potentially publicly accessible Power Pages instances during its investigation, although this does not mean that every identified portal was exposing sensitive information.

By August 7, ExfilSquad had reportedly published data associated with 13 organizations. Its claimed victims span government, education, aviation, insurance, manufacturing and technology. Organizations named by the group include Allstate, the cities of Atlanta and Houston, District of Columbia Public Schools, the UK’s Department for Education, Frontier Airlines, Newcastle University, TaylorMade, Sun Day Red, Viavi Solutions and Wesco International.

The attackers claim individual datasets contain millions of records. The purported Houston collection is described as containing roughly six million records, while approximately three million are attributed to Atlanta and 2.4 million to Frontier Airlines. These numbers originate from ExfilSquad and should not be treated as independently confirmed figures.

According to descriptions of the leaked material, exposed records can include names, addresses, contact details, customer service information, recruitment records, employee information, student data, case histories, and other business information. The precise contents vary between the claimed victims.

The campaign highlights the security consequences of configuration errors in cloud-connected portals. A system does not necessarily need to contain an exploitable software vulnerability for attackers to obtain information if access permissions unintentionally make private Dataverse records available without authentication.

Organizations operating Power Pages should therefore review anonymous table permissions and determine exactly what unauthenticated visitors can retrieve. Security teams should also examine affected portal configurations and logs, identify potentially exposed records, and rotate credentials or API keys if such information was accessible.

At present, the evidence described by Fortra points toward data exposure through SaaS environments rather than traditional ransomware intrusions. There is no confirmed Dynamics 365 vulnerability behind the campaign, making the configuration of publicly accessible Power Pages portals the central concern.

Leave a Reply