ExfilSquad Leak Analysis Confirms 13 Victims
Fortra researchers verified ExfilSquad's access to sensitive data from 13 organizations, likely via misconfigured Power Pages portals.
The data extortion group ExfilSquad has been connected to leaked information from at least 13 organizations, with new analysis confirming the criminals' claims of accessing sensitive data. Fortra's Intelligence and Research Experts (FIRE) reviewed public data samples and concluded the group's assertions are accurate.
A Rapid Emergence and Escalation
ExfilSquad first appeared on July 26 and has claimed to have exfiltrated data from 15 separate organizations. On August 7, data dumps for 13 of these victims were published via torrents, with the group alleging those organizations failed to meet their demands.
The full archive, named “[victim]_exfilsquad,” was made available for download. According to Fortra, the total data released amounts to 382.64 GB and includes 27 million records across the 13 victims.
Victims Include Government and Educational Entities
The confirmed victims span multiple sectors, including government, education, financial services, and manufacturing. Among them are the City of Atlanta (atlantaga.gov), the UK Department for Education (education.gov.uk), and the UK Police National Legal Database.
District of Columbia Public Schools (DCPS) was also listed by the attackers. In a note accompanying the leak, the group stated: “We are not going to dox a bunch of school children, but we are going to expose how incompetent DCPS is at keeping children as young as six's information safe. Thus, we are releasing a censored version of the leak and have shredded the original entirely from our servers.”
In this instance, 60,000 records containing student names, dates of birth, and unique student identifiers—among other personally identifiable information (PII)—were leaked.
Missing Victims from the Initial List
The Fortra team noted that Zenith Bank Plc and Analog Devices were not present in the published data, despite being included in the original 15-victim list. The reasons for their absence remain unclear.
Likely Attack Vector: Misconfigured Power Pages
The researchers said the data breaches are most likely limited to unauthorized access of Microsoft D365 CRM and ERP instances. They wrote: “The leading theory on the initial attack vector that enabled exfiltration is misconfigured Microsoft Power Page portals that allowed for public read access.”
Power Pages is a SaaS platform for creating, hosting, and administering external-facing business websites. The leaked data formations were consistent with Microsoft Dataverse exports, suggesting unauthorized read access was likely achieved during the incidents.
How the Attackers Identified Targets
Victims were likely identified through crawling for misconfigured Microsoft Power Portals or other enumeration techniques. The Fortra researchers noted that because the data breach reached just 15 victims, rather than tens of thousands, it is unlikely that a D365 vulnerability was the source.
They also highlighted a known issue in Microsoft Power Pages: when the Anonymous Users web role is assigned to a table permission, the table’s data can be read by anyone visiting the site. The Power Pages can be accessed via an API at https:///_api/*. Microsoft advises against using this role in publicly exposed sites in their documentation.
Scale of Exposure
Automated scanning for exposed Power Pages sites is a known technique, Fortra noted. In its research, the firm said it was able to identify over 10,000 potential Power Pages instances accessible to the public.
The findings underscore the risk posed by misconfigured cloud services, particularly those involving Microsoft's Power Platform. Organizations using Power Pages need to review their table permissions and ensure the Anonymous Users role is not enabled on publicly accessible sites.
Why This Matters for Organizations
The confirmation of ExfilSquad's access highlights the real-world consequences of misconfiguration in widely used enterprise platforms. For businesses running Microsoft D365 or Power Pages, this serves as a critical reminder that even a single misconfigured portal can lead to significant data exposure.
The fact that ExfilSquad could access and publish data from multiple high-profile victims, including government and educational institutions, suggests that attackers are actively scanning for such weaknesses. Organizations should prioritize auditing their Power Pages environments, restricting anonymous access, and monitoring for unusual API requests.
As data extortion groups continue to evolve, the emphasis on proper configuration and access controls becomes ever more crucial. This incident may prompt a broader reassessment of how cloud-based portals are secured across sectors.
Sources
- Infosecurity Magazine Original source
Continue Reading
Scammers exploit Shopify's app to fake refunds
Fraudsters abuse Shopify's notification system, embedding contact info in shipping addresses to trick victims into sending money.
RingCentral Breach Exposes 1.6M Accounts
ShinyHunters leaks data from 1.6 million RingCentral accounts after July hack.
Evooo1Bot Botnet Weaponizes Edge Device Flaws
A new Mirai-based Linux botnet uses encrypted C2, SOCKS proxies, and exploits in routers to hijack edge devices.