ExfilSquad Leaks 27 Million Records via Misconfigured Microsoft Power Pages
A new extortion group is releasing massive datasets after organizations failed to secure anonymous access permissions in their SaaS portals.
A new data extortion group known as ExfilSquad has claimed the theft of over 27 million records from 13 different organizations. The breach underscores a systemic failure in how companies configure public-facing portals, turning a convenience tool into a massive security liability.
According to reports from Cybernews, the group targeted organizations across the government, education, aviation, and finance sectors. ExfilSquad began releasing hundreds of gigabytes of data via torrent files after victims allegedly missed a payment deadline on August 5. The scale of the heist is significant: the group claims to have stolen approximately 6 million records from the City of Houston, 3 million from the City of Atlanta, 2.4 million from Frontier Airlines, and 2 million from TaylorMade/Sun Day Red. The UK Department for Education is also among the confirmed victims.
The Configuration Gap
The breach was not the result of a software vulnerability or a zero-day exploit in Microsoft Dynamics 365. Instead, the attackers exploited misconfigured anonymous access permissions within Microsoft Power Pages. Power Pages allows organizations to build external websites that interact with business data stored in Microsoft Dataverse. However, if table permissions are improperly set, internal datasets that should be restricted to authenticated users become visible to any anonymous visitor on the internet.
Fortra Intelligence and Research Experts (FIRE) highlighted the breadth of this risk, identifying over 10,000 potential public-facing Power Pages instances that could be susceptible to similar exposure. Fortra researchers noted that while the breach is valid, it likely does not represent a full organizational-level compromise, as the stolen data appears limited to the SaaS environment.
Industry Implications
This incident demonstrates a shift in attacker methodology, where hackers are actively scanning for low-hanging fruit in low-code/no-code platforms. By targeting SaaS configurations, ExfilSquad was able to exfiltrate massive amounts of data without needing to penetrate a corporate network or deploy complex malware. It serves as a warning that the ease of deploying cloud portals often comes with a hidden cost: the requirement for rigorous, manual permission auditing.
ExfilSquad, which first appeared on July 26, 2026, has used the breach to publicly shame the victims' security postures. In one instance, the group stated they would not doxx school children but intended to expose how "incompetent" the DCPS was at keeping the information of children as young as six safe.
What to Watch
Security teams are now urged to audit their Power Pages table permissions to ensure that anonymous access is disabled for sensitive Dataverse tables. As more organizations adopt low-code platforms to accelerate digital transformation, the industry must determine if automated configuration auditing can keep pace with the speed of deployment. It remains to be seen if other extortion groups will adopt this specific scanning technique to target the thousands of other exposed instances identified by Fortra.