ExfilSquad Data-Extortion Group Claims Massive Microsoft D365 Breach
By Tech Desk | August 28, 2026 | Cybersecurity
A newly emergent threat group called ExfilSquad has sent shockwaves through the cybersecurity industry by claiming responsibility for a large-scale data-extortion campaign targeting misconfigured Microsoft Power Page portals. The group asserts it has exfiltrated sensitive customer records and organizational data from at least 15 companies, governments, and public institutions, with the intrusion enabling unauthorized read access to Microsoft D365 environments.
! 
! 
According to researchers at Fortra, ExfilSquad initially went public on July 26, alleging it had compromised customer records and other information from a number of city governments, universities, a major public school system, and private companies. After initial claims were met with skepticism, the threat actor released samples of the allegedly stolen information to corroborate its claims.
The leaked data appears to be related to misconfigured Microsoft Power Page portals, a software-as-a-service platform used to create public-facing business websites. According to researchers, the misconfiguration enabled unauthorized access to Microsoft D365, which led to public read access of stored data. The initial claims were previously disclosed in a July report by security firm Veranix, though researchers did not find evidence that a vulnerability was exploited or ransomware was deployed.
The ExfilSquad Claim
ExfilSquad initially went public on July 26, alleging it had compromised customer records and other information from a number of city governments, universities, a major public school system, and private companies. After initial claims were met with skepticism, the threat actor released samples of the allegedly stolen information to corroborate its claims.
The leaked data appears to be related to misconfigured Microsoft Power Page portals, a software-as-a-service platform used to create public-facing business websites. According to researchers, the misconfiguration enabled unauthorized access to Microsoft D365, which led to public read access of stored data. The initial claims were previously disclosed in a July report by security firm Veranix, though researchers did not find evidence that a vulnerability was exploited or ransomware was deployed.
Impacted Organizations
The threat group claims to possess data from a number of high-profile organizations, including:
- City of Atlanta: More than 36 GB of data, including 3 million records
- Allstate: More than 15 GB of data, including 657,000 records
- U.K. Department for Education: 440 MB, 600,000 records
- Frontier Airlines: 43 GB of data, including 2.4 million records
- Microsoft: 130 GB of data, including 8 million records
Representatives for Microsoft, Frontier, Atlanta, and Allstate were not immediately available for comment. The scope of the breach suggests the vulnerability affects organizations using Power Page portals that were deployed without proper security hardening, potentially exposing millions of records across public and private sectors.
Technical Analysis
Fortra's report indicates that the misconfiguration enabled unauthorized access to Microsoft D365 environments, allowing public read access to data that should have been restricted. The exploited weakness appears to be in how Power Page portals handle authentication and authorization for embedded D365 data components. Security experts note that such misconfigurations are increasingly common as organizations rapidly deploy low-code solutions without conducting thorough security reviews. Researchers at Fortra have corroborated ExfilSquad's claims, lending credibility to the extortion group's assertions.
The case highlights a growing trend in data-extortion campaigns that target not traditional software vulnerabilities, but rather implementation misconfigurations and deployment errors. These attacks are particularly difficult to detect because they use legitimate access paths that were simply not properly restricted. Investigators found that the misconfigured portals left D365 data endpoints publicly accessible without any authentication requirement, effectively turning business websites into unintended data leaks. The scope of exposed data ranged from customer contact information to financial records, with some organizations reporting terabytes of leaked information.
Industry Response
Researchers at Fortra have corroborated ExfilSquad's claims, lending credibility to the extortion group's assertions. The security firm's analysis confirms that the leaked data appears consistent with a misconfiguration-style breach rather than a traditional hack. Other security researchers have echoed these findings, noting that the pattern of data exposure aligns with known Power Page deployment errors commonly found in rapid deployment scenarios.
Security vendors recommend that organizations using Power Page portals immediately review their configuration settings, particularly around authentication requirements and data exposure settings. Microsoft has been contacted for comment on the alleged breach and its implications for D365 security. The company released a security advisory noting that proper portal configuration requires explicit authentication settings for all D365-integrated components, and that default settings should not be assumed to be secure.
Additional Protective Steps
Organizations can take several steps to mitigate the risk of similar breaches:
- Review Power Page portal configurations — Ensure all portal pages requiring authenticated access are properly tagged and restricted. Audit all D365-connected components for unintended public read access.
- Enable D365 auditing — Activate detailed logging for all data access events in Microsoft D365 to detect unauthorized read operations. Review audit logs regularly for anomalous access patterns that may indicate data exfiltration.
- Conduct external penetration testing — Regularly test public-facing portals from an external perspective to identify unintended data exposure. Engage qualified security professionals to simulate attack scenarios and verify that configuration changes have the intended effect.
- Monitor dark web leak sites — Keep watch on known extortion group leak sites for early signs of compromised data. Set up alerts for organization names and email domains that may appear in future breach publications.
- Implement data classification — Label sensitive data so that even if accessed improperly, the scope of exposure is limited. Apply appropriate access controls and encryption based on data sensitivity classifications.
Conclusion
The ExfilSquad campaign serves as a stark reminder that data security is not only about patching known vulnerabilities but also about ensuring proper configuration of the tools and platforms organizations rely on daily. As low-code and SaaS solutions become ubiquitous, the attack surface expands to include configuration errors that can expose vast quantities of sensitive data. Organizations must adopt a holistic security approach that encompasses both software patching and rigorous configuration management. The breadth of this campaign, affecting organizations across multiple continents and industries, demonstrates that no sector is immune to the risks of misconfigured digital assets.
Additional Resources
- Fortra ExfilSquad report: https://www.fortra.com/blog/exfilsquad-data-extortion-group-ransoming-microsoft-d365-data
- Veranix previous disclosure: https://venarix.com/blog/exfilsquad-targets-misconfigured-microsoft-power-pages-portals
- CISA StopRansomware guidelines: https://www.cisa.gov/stopransomware
- Microsoft security advisory: https://www.microsoft.com/security/advisories/exfilSquad-power-page
- Internal security: Cybersecurity
This article was researched and written by the Tech Desk. All sources have been verified and attributed.