A cybercrime group calling itself ExfilSquad has leaked 382.64 gigabytes of sensitive information from 13 organizations after allegedly exploiting misconfigured Microsoft Power Pages portals, according to new analysis published by Fortra Intelligence and Research Experts. The victims span government agencies, schools, financial institutions, and manufacturing firms, with the leaked data totaling roughly 27 million records. Researchers at FIRE reviewed samples of the leaked information and confirmed the attackers' claims of accessing sensitive data are accurate.
The extortion campaign first surfaced on July 26, when the group claimed it had stolen data from 15 separate organizations, the Fortra team reported. On August 7, the criminals published data dumps for 13 of those victims via torrents, stating the organizations "did not meet the agreements." High-profile targets included the City of Atlanta, the UK Department for Education, the UK Police National Legal Database, and District of Columbia Public Schools. For the DCPS breach, the attackers released a "censored version" containing 60,000 records with student names, birth dates, and unique identifiers, claiming they had "shredded the original entirely from our servers" to avoid exposing children as young as six. Two organizations from the original list of 15—Zenith Bank Plc and Analog Devices—did not appear in the published data dumps.
The researchers concluded that the breaches likely stemmed from unauthorized access to Microsoft D365 CRM and ERP instances, with the "leading theory" pointing to misconfigured Microsoft Power Pages portals that permitted public read access. The leaked data structures matched Microsoft Dataverse exports, suggesting attackers achieved unauthorized read privileges during the incidents. The FIRE team noted that because only 15 victims were hit—rather than tens of thousands—a broader D365 vulnerability is unlikely to be the root cause. Instead, the criminals probably identified targets by crawling for misconfigured Power Portals or using other enumeration methods.
The report highlights a known security issue in Microsoft Power Pages: when the Anonymous Users web role gets assigned to a table permission, anyone visiting the site can read that table's data. Power Pages, a software-as-a-service platform for building external business websites, can be accessed through an API at addresses like https://
The scale of exposed Power Pages portals suggests organizations may be inadvertently opening the door to extortion campaigns by failing to follow Microsoft's security guidance on access controls. For IT leaders weighing the convenience of external portals against the risk of data theft, this incident illustrates how a single misconfiguration can transform a productivity tool into a liability that invites criminal exploitation.

