Key Takeaways
- Fortra validated sensitive data linked to at least 13 ExfilSquad victims across government, education, financial services and manufacturing.
- Researchers suspect publicly readable Microsoft Power Pages configurations, rather than a vulnerability in Microsoft D365, enabled the theft.
- The campaign shows how extortion groups can monetize exposed SaaS data without deploying ransomware or disrupting operations.
ExfilSquad has published data associated with at least 13 organizations after finding Microsoft Power Pages portals that exposed underlying business records to unauthenticated users, according to new research from Fortra Intelligence and Research Experts (FIRE).
The data-extortion group, which first appeared on July 26, originally claimed to have stolen information from 15 organizations. On August 7, it distributed data dumps connected to 13 victims through torrents, stating those organizations had failed to meet agreements.
FIRE examined publicly released samples and concluded that ExfilSquad’s claims of access to sensitive information were credible. The combined archive, labeled using the format "[victim]_exfilsquad," reportedly contained 382.64 GB of data and 27 million records.
Named victims included the City of Atlanta, the UK Department for Education and the UK Police National Legal Database.
The intrusion path centers on data structures consistent with Microsoft Dataverse exports. This points toward unauthorized read access involving Microsoft D365 CRM and ERP environments, rather than ransomware deployment or a previously unknown software vulnerability.
“The leading theory on the initial attack vector that enabled exfiltration is misconfigured Microsoft Power Page portals that allowed for public read access,” the FIRE team wrote.
Power Pages allows organizations to create and manage external-facing business websites connected to enterprise data. A configuration problem can emerge when the Anonymous Users web role is assigned table permissions. Depending on the permissions granted, a visitor may then be able to read table data without authenticating, including through the platform’s API.
Microsoft’s Power Pages documentation advises administrators to use the Anonymous Users role carefully on publicly exposed sites to ensure access rules reflect the sensitivity of the connected data.
While low-code platforms make it easier for business units to publish applications, they expand the configuration-review burden. Security teams monitoring identities, endpoints and cloud infrastructure must also ensure public portals do not inadvertently expose CRM or ERP tables.
FIRE identified more than 10,000 potential Power Pages instances accessible from the public internet, illustrating the size of the searchable environment available to attackers using automated crawling and enumeration to locate misconfigurations.
The limited victim set, 15 initially claimed targets, further supports the misconfiguration theory. A broadly exploitable product vulnerability would likely produce a significantly higher number of victims, whereas this scale is consistent with attackers identifying specific individual portals with incorrectly set permissions.
The campaign aligns with a broader shift toward exfiltration-only extortion. Cybersecurity Dive reported that researchers validated the group’s theft claims and linked the activity to exposed Power Pages configurations. Concurrently, ENISA research published through Traficom tracked ransomware and related data-theft extortion at more than 1,000 claims per quarter globally, noting that many groups now bypass encryption entirely to rely on data-leak pressure.
To mitigate these risks, security teams should inventory Power Pages deployments, review Anonymous Users permissions, test API access from unauthenticated sessions and determine which Dataverse tables are reachable.
Frameworks such as NIST CSF 2.0 and ISO/IEC 27001 structure these tasks within broader configuration management, data governance and incident-response programs. Tools and services from Mandiant, CrowdStrike and Recorded Future also support investigation and threat tracking for public-facing SaaS configurations, which can be exploited for extortion even without malware deployment or system encryption.
⬇️