Breaches · 55 days ago
Fortra researchers corroborated ExfilSquad’s July 26 breach claims and tied the alleged exfiltration to misconfigured Microsoft Power Pages portals that exposed Microsoft Dynamics 365 data across governments, schools, airlines, insurers, and private companies. The group says it holds records from roughly 15 organizations, including Atlanta, Allstate, the U.K. Department for Education, Frontier Airlines, and Microsoft.
The break is in the portal, not the backend app. Power Pages is a public-facing website layer; when it is wired to D365 with the wrong access settings, outsiders can read records they were never meant to see, so a healthy core system can still leak data through its front door.
For teams that publish customer or citizen records through portals, the exposure sits in that trust link between the public site and the SaaS data behind it. A compromise of the portal layer can create broad data loss without ransomware or a server exploit, and the backend may remain untouched.
3 sources covering this story
Researchers Confirm ExfilSquad’s Access to Sensitive Data
Researchers have verified that ExfilSquad possesses sensitive data stolen from at least 13 victims after the extortion group published leaked datasets via torrents
Researchers confirm breach claims by data-extortion group
The exfiltrated data may be related to misconfiguration of Microsoft Power Page portals, according to a new report.
Terabytes of credentials leaked in massive supply-chain attack
The data was scraped and exfiltrated from 2,500 users of a compromised AI package.
Part of the PlainSec briefing for 2026-08-15