Mastodon Skip to content
live markets
S&P 5007,692.18▲ 2.44%NASDAQ26,243.36▲ 1.57%DOW53,239.51▲ 1.94%GOLD4,664.40▲ 14.57%WTI86.67▲ 2.07%BRENT94.15▲ 3.45%EUR/USD1.1684▲ 2.33%USD/JPY158.92▼ 2.20%DXY98.84▼ 2.32%BTC$77,483▲ 7.80%ETH$2,400▲ 5.00%SOL$91.61▲ 6.20%TOTAL CRYPTO$2.62T▲ 3.73%
pulseofnations.
UTC --:--NYC --:--LON --:--WAW --:-- bluesky ↗ Join the wire

27M Records Exposed Via Misconfigured Microsoft Power Pages

Extortion group ExfilSquad claims to have stolen over 27 million records from 13 organizations including governments and airlines through publicly accessible Microsoft Power Pages portals.

Partner Surfshark VPN

An emerging data extortion group called ExfilSquad claims to have exfiltrated more than 27 million records from 13 organizations, exploiting misconfigured Microsoft Power Pages portals connected to Dynamics 365 Dataverse environments that left sensitive databases exposed to anonymous internet visitors.

Fortra Intelligence and Research Experts (FIRE) analyzed data samples published by the group and concluded that the breach appears valid, though it likely does not represent a full organizational-level compromise. Instead, the evidence points to publicly accessible Microsoft Power Pages sites that inadvertently exposed internal Dataverse data to anyone browsing the web without authentication.

Victims Span Governments, Airlines, and Schools

The list of alleged victims is striking in its breadth. Among the organizations named by ExfilSquad are Allstate, the City of Atlanta, the City of Houston, Frontier Airlines, the UK Department for Education, DC Public Schools, Newcastle University, TaylorMade, and the UK Police National Legal Database. The City of Houston dataset alone allegedly contains approximately 6 million records, while Atlanta accounts for roughly 3 million and Frontier Airlines for 2.4 million.

The stolen data reportedly includes names, addresses, contact information, customer service records, employee information, recruitment data, student information, case histories, and other corporate records. ExfilSquad said it censored the DC Public Schools release, stating it would not publish children’s personal data but wanted to expose the school system’s security failures.

Misconfiguration, Not Vulnerability

Fortra’s investigation found no evidence of a software vulnerability in Dynamics 365 itself. Rather, the researchers identified over 10,000 potential Power Pages instances accessible to the public, where organizations had failed to configure proper table permissions. Microsoft’s own documentation warns that assigning certain permissions to anonymous users can allow anyone to read underlying data, but many organizations apparently did not implement these restrictions.

Our analysis suggests that this is a valid data breach, although it is unlikely to represent a full organizational-level compromise, as the data appears to be limited to SaaS.

The group first appeared on July 26, initially claiming to have compromised 15 organizations, then began publishing data samples two days later. By August 7, ExfilSquad had released torrent files for 13 victims after the alleged extortion deadline of August 5 passed without payment. Two organizations, Zenith Bank and Analog Devices, were subsequently removed from the list under unclear circumstances.

Security experts recommend that organizations using Power Pages immediately audit their portals, disable anonymous access to business data, preserve logs, and review connected services such as Power Automate, SharePoint, and Power BI. The Power Pwn module can be used to test specific portals for anonymous access to Dataverse tables.

Sources: Cybernews; Fortra FIRE; BleepingComputer

React to this dispatch
Share this dispatch X WhatsApp Report an error

discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Next dispatch Slovakia Finds Russian Backdoors in EU-Funded Speed Cameras Read →