Published Security3 min read
Fortra says ExfilSquad's dumps check out: 382.64 GB, 27 million records, 13 victims
Researchers reviewed the new extortion brand's leaks and found real data from Atlanta, the UK Department for Education and 11 others. The likely way in was a Power Pages permission.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- Fortra Intelligence and Research Experts (FIRE) reviewed data samples made public by the ExfilSquad group and concluded that the criminals' claim they have access to sensitive data is correct.
- New analysis tied ExfilSquad to leaked data from at least 13 victims from sectors including government, education, financial services and manufacturing.
- The ExfilSquad group first emerged on July 26.
- ExfilSquad has claimed to have exfiltrated the data of 15 separate organizations.
- On August 7, data dumps of 13 of the victims were published via torrents.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Fortra's Intelligence and Research Experts team reviewed the data samples ExfilSquad made public and concluded that the group's claim to hold sensitive data is correct, tying it to leaks from at least 13 organisations across government, education, financial services and manufacturing [1][2]. For public-sector defenders that changes the job from monitoring a new criminal brand's marketing to triaging a confirmed loss.
The group first surfaced on July 26 and claimed to have exfiltrated data from 15 organisations [3][4]. On August 7, twelve days later, dumps for 13 of them went out via torrents, with the group saying those victims had not met the agreements [5][6][1]. Each archive was named "[victim]_exfilsquad" and the totals were reported at 382.64 GB and 27 million records [7][8]. That averages roughly 2.1 million records and about 29 GB per victim, which is a size consistent with database exports rather than opportunistic file grabs [2].
The named victims include the City of Atlanta, the UK Department for Education and the UK Police National Legal Database [9]. District of Columbia Public Schools was also listed, with a note from the attackers saying they were "not going to dox a bunch of school children" but would "expose how incompetent DCPS is at keeping children as young as six's information safe", and that they had released a censored version and shredded the original [10]. Even censored, 60,000 records containing student names, dates of birth, unique student identifiers and other personally identifiable information were leaked [11]. The shredding claim is the group's own, and Fortra reported no verification of it [10].
Zenith Bank Plc and Analog Devices appeared on the original list of 15 but not in the dumps, according to the FIRE team [12], which leaves two claimed victims unpublished [1].
On mechanism, Fortra assesses the breaches are most likely limited to unauthorised access of Microsoft Dynamics 365 CRM and ERP instances, with the leading theory being misconfigured Microsoft Power Pages portals that allowed public read access [13][14]. Power Pages is Microsoft's software-as-a-service platform for building and hosting external-facing business websites [15]. The leaked data formations were consistent with Microsoft Dataverse exports, which Fortra says points to unauthorised read access rather than deeper compromise [16]. Victims were probably found by crawling for misconfigured portals or other enumeration [17], and because the count reached 15 rather than tens of thousands, the researchers consider a D365 product vulnerability unlikely as the source [18].
The specific failure mode is documented. When the Anonymous Users web role is assigned to a table permission in Power Pages, that table's data can be read by anyone visiting the site [19], and the data is reachable through the portal API at /_api/* [20]. Microsoft's own documentation advises against using that role on publicly exposed sites [21]. Automated scanning for exposed Power Pages sites is a known technique, and Fortra said it identified more than 10,000 potential Power Pages instances accessible to the public [22][23].
Watch three things. Whether the two withheld dumps land, since their absence implies negotiation or a failed claim rather than restraint [1][12]. Whether the named public bodies confirm the scope, particularly the 60,000 student records, which carries notification duties [11][9]. And whether other crews start working the same crawl, because the 10,000-plus exposed instances Fortra counted are a standing inventory available to anyone who repeats the technique [22][23].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Fortra Intelligence and Research Experts (FIRE) reviewed data samples made public by the ExfilSquad group and concluded that the criminals' claim they have access to sensitive data is correct.
ReportedSource: Fortra Intelligence and Research Experts (FIRE), via Infosecurity MagazineView cited source - [2]
New analysis tied ExfilSquad to leaked data from at least 13 victims from sectors including government, education, financial services and manufacturing.
ReportedView cited source - [4]
ExfilSquad has claimed to have exfiltrated the data of 15 separate organizations.
ReportedView cited source - [5]
On August 7, data dumps of 13 of the victims were published via torrents.
ReportedView cited source - [6]
The criminal group claimed the 13 organizations whose data it published did not meet the agreements.
ReportedView cited source
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- infosecurity-magazine.comAug 14Researchers Confirm ExfilSquad’s Access to Sensitive Data Across 13 Organizations
Additional citations
- Fortra Intelligence and Research Experts (FIRE), via Infosecurity Magazine
- ExfilSquad note, as reported by Infosecurity Magazine
- Fortra FIRE team
- Fortra
- Fortra researchers
- Microsoft documentation, cited by Fortra



