Published Security3 min read
ExfilSquad's 382GB haul may trace to one Power Pages permission, not malware
Fortra researchers say the extortion crew likely read Dynamics 365 data straight out of portals where a table was exposed to the Anonymous Users web role.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- ExfilSquad emerged on July 26 and initially claimed to have exfiltrated data from 15 organizations; the eventual 13 published victims spanned sectors including government, education, financial services and manufacturing.
- By August 7, data dumps from 13 victims were published via torrents, totaling 382.64 GB and approximately 27 million records.
- FIRE reviewed data samples publicly released by the group and confirmed the validity of the group's claims.
- Researchers theorize that the breaches resulted from unauthorized access to Microsoft D365 CRM and ERP instances, likely enabled by misconfigured Microsoft Power Pages portals that allowed public read access.
- The issue is one where an Anonymous Users web role assigned to a table permission grants anyone visiting the site read access, and this is a known issue.
Compiled by The WatchSomething wrong?How this is made
Why it matters
A new data extortion group called ExfilSquad has published torrents containing data from 13 organisations, totalling 382.64 GB and roughly 27 million records, and researchers at Fortra Intelligence and Research Experts (FIRE) believe the collection required no malware at all [2][4]. FIRE's theory is that the group reached Microsoft Dynamics 365 CRM and ERP data through misconfigured Power Pages portals that allowed public read access [4].
The mechanism is not a novel exploit. When a table permission in Power Pages is assigned to the Anonymous Users web role, anyone who visits the site can read that table, and FIRE describes this as a known issue [5]. According to the researchers, the group probably built its victim list by crawling the internet for portals in that state [6]. That inverts the usual assumption about targeting: the selection criterion was not sector, size or revenue but the presence of an internet-reachable portal with a table left open. The published spread is consistent with that, covering government, education, financial services and manufacturing [1].
The named victims are not obscure. FIRE's review lists the City of Atlanta, the UK Department for Education and the UK Police National Legal Database [7]. The group also hit District of Columbia Public Schools and released a censored version of 60,000 student records containing personally identifiable information [8].
Two numbers are worth holding onto. ExfilSquad surfaced on July 26 and the dumps were out by August 7, which is 12 days from first appearance to bulk publication [1][2][1]. And the average victim contributed about 29 GB and roughly 2.1 million records [2][3], which is the shape of a database export rather than an operator picking through file shares. Speed and volume both point the same way as FIRE's theory: reading, not intruding.
Two cautions on the reporting. First, FIRE's confirmation covers authenticity, not cause. The researchers reviewed samples the group released publicly and confirmed the claims were valid [3]; the Power Pages explanation is described as a theory [4], relayed via Infosecurity Magazine [9], and is currently single-sourced. Second, the source material calls these portals misconfigured [4]. It does not say the anonymous read behaviour is a shipped default, and nobody running D365 portals should tell their board it was Microsoft's fault until that is established.
None of that changes what an operator can do this week, because the audit is cheap either way. If your organisation runs Power Pages, the specific thing to enumerate is every table permission bound to the Anonymous Users web role, since that is the binding FIRE identifies as granting read access to any visitor [5]. This is a configuration review, not an incident response exercise, and it does not depend on the attribution holding up.
Watch three things. Whether the remaining two victims appear: ExfilSquad initially claimed 15 organisations and published 13, leaving two unaccounted for [1][2][4]. Whether a second research team corroborates the Power Pages route, which would move it from theory to root cause. And whether Microsoft adjusts guidance or defaults around anonymous table permissions, which would be the clearest signal that the exposure was broader than a handful of careless deployments.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
ExfilSquad emerged on July 26 and initially claimed to have exfiltrated data from 15 organizations; the eventual 13 published victims spanned sectors including government, education, financial services and manufacturing.
ReportedSource: Fortra Intelligence and Research Experts (FIRE), via Infosecurity Magazine and SC MediaView cited source - [2]
By August 7, data dumps from 13 victims were published via torrents, totaling 382.64 GB and approximately 27 million records.
- [3]
FIRE reviewed data samples publicly released by the group and confirmed the validity of the group's claims.
- [4]
Researchers theorize that the breaches resulted from unauthorized access to Microsoft D365 CRM and ERP instances, likely enabled by misconfigured Microsoft Power Pages portals that allowed public read access.
- [5]
The issue is one where an Anonymous Users web role assigned to a table permission grants anyone visiting the site read access, and this is a known issue.
- [6]
Attackers likely identified victims by crawling for these exposed portals.
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- scworld.comSC StaffAug 14ExfilSquad data extortion group linked to 13 victim data leaks
Additional citations
- Fortra Intelligence and Research Experts (FIRE), via Infosecurity Magazine and SC Media
- FIRE, via Infosecurity Magazine and SC Media



