Infosecurity

ExfilSquad’s Data Leaks: 13 Organizations Exposed, Researchers Confirm

Published

on

ExfilSquad’s Claims Check Out

New research from Fortra’s Intelligence and Research Experts (FIRE) has confirmed that the ExfilSquad data extortion group really did get its hands on sensitive data. The criminals claimed they had exfiltrated information from 15 organizations. Now, the evidence shows they weren’t bluffing.

FIRE reviewed the public data samples and concluded that the group’s access to sensitive data is real. At least 13 victims have been hit, spanning government, education, financial services, and manufacturing. That’s not a small-time operation.

The group first surfaced on July 26. By August 7, they had published data dumps for 13 of the 15 claimed victims via torrents, saying those organizations didn’t meet their demands. The full archive, named “[victim]_exfilsquad,” was up for download. The total haul? A staggering 382.64 GB and 27 million records.

Who Got Hit?

The victim list reads like a cross-section of public and private sectors. The City of Atlanta (atlantaga.gov), the UK Department for Education (education.gov.uk), and the UK Police National Legal Database all appear. The District of Columbia Public Schools (DCPS) is also on the list.

For DCPS, the attackers took an unusual stance. They wrote: “We are not going to dox a bunch of school children, but we are going to expose how incompetent DCPS is at keeping children as young as six’s information safe. Thus, we are releasing a censored version of the leak and have shredded the original entirely from our servers.”

In that case, 60,000 records were leaked, containing student names, dates of birth, and unique student identifiers—classic personally identifiable information (PII).

Notably, Zenith Bank Plc and Analog Devices were on the original 15-victim list but didn’t appear in the dumps. The FIRE team flagged this as a possible sign that those negotiations went differently, or the data wasn’t ready to be released.

The Likely Attack Vector: Misconfigured Microsoft Power Pages

So how did ExfilSquad pull this off? Fortra’s researchers believe the breaches stem from unauthorized access to Microsoft D365 CRM and ERP instances. The leading theory? Misconfigured Microsoft Power Page portals that allowed public read access.

Power Pages is a SaaS platform for building external-facing business websites. If set up wrong, it can expose data to anyone who knows where to look. The leaked data formations matched Microsoft Dataverse exports, which suggests unauthorized read access was achieved during the incidents.

The attackers probably found their targets by crawling for misconfigured Power Portals or using other enumeration techniques. It wasn’t a sophisticated zero-day exploit. It was a configuration error—and that’s what makes it so dangerous.

Why It’s Not a D365 Vulnerability

Fortra was quick to note that because the breach hit only 15 victims, not tens of thousands, a systemic vulnerability in D365 is unlikely. Instead, the issue is specific to how Power Pages is configured.

There’s a known problem: when the Anonymous Users web role is assigned to a table permission, anyone visiting the site can read the table’s data. Power Pages can be accessed via an API at https://<portal>/_api/*. Microsoft’s own documentation advises against using this role in publicly exposed sites, but not everyone follows the guidance.

Fortra’s research even found over 10,000 potential Power Pages instances accessible to the public. That’s a lot of attack surface.

What This Means for Organizations

This incident is a wake-up call. Data extortion groups like ExfilSquad are actively scanning for misconfigured systems. They don’t need to break in—they just need a door left open.

For any organization using Microsoft Power Pages or D365, the takeaway is clear: audit your table permissions, disable Anonymous Users roles on public sites, and monitor API access. A few minutes of configuration review could save you from a 382 GB leak.

If you’re dealing with a similar threat, understanding the data extortion group tactics can help you prepare. And if you’re using Microsoft Power Pages security settings, double-check them now.

The ExfilSquad data leak is a reminder that cybercriminals are patient and methodical. They find the weak spots, and they exploit them. Don’t be the next headline.

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending

Exit mobile version