A data extortion group claims it stole more than 27 million records from 13 organisations through publicly exposed Microsoft Power Pages portals.

Researchers at Fortra say the incident does not appear to involve a vulnerability in Microsoft Dynamics 365. Instead, the available evidence points to Power Pages sites that may have granted anonymous visitors access to data stored in Microsoft Dataverse.

Microsoft Power Pages data breach claims affect 13 organisations

The group, known as ExfilSquad, appeared in late July and claimed to have compromised 15 organisations. It later published data samples and torrent files that it said came from 13 victims.

Fortra analysed the published samples and said they appear consistent with a genuine breach. However, researchers found no evidence that attackers gained full access to victims’ internal networks.

The stolen data appears to come mainly from cloud-based Dynamics 365 CRM and ERP environments. It reportedly includes customer, employee, student and business information.

ExfilSquad claims it stole around six million records from the City of Houston, three million from the City of Atlanta and 2.4 million from Frontier Airlines. It also lists TaylorMade and Sun Day Red with roughly two million records.

Misconfigured portals may have exposed Dataverse data

Power Pages allows organisations to build public-facing websites and portals connected to Microsoft Dataverse. Businesses can use these sites for customer services, partner portals, employee access and public information requests.

However, the platform can expose sensitive data if administrators assign excessive table permissions to anonymous users.

Microsoft’s own documentation warns that some anonymous permissions can allow visitors to read Dataverse records without signing in. If an organisation misconfigures those permissions, outsiders may be able to browse or download far more information than intended.

Fortra identified more than 10,000 potentially public Power Pages instances. The researchers believe ExfilSquad may have searched for exposed sites, identified overly broad anonymous access and extracted data directly from Dataverse.

The investigation found no signs of ransomware encryption, lateral movement through corporate networks or a broad software exploit affecting Dynamics 365.

Governments, schools and companies appear on leak site

The alleged victims span government, education, finance, aviation, manufacturing, technology and law enforcement.

Organisations named by ExfilSquad include Allstate, the City of Atlanta, Bonava, District of Columbia Public Schools, the UK Department for Education, Frontier Airlines, the City of Houston, Newcastle University and Wesco International.

The group also named the UK Police National Legal Database, Viavi Solutions, TaylorMade and Sun Day Red.

ExfilSquad removed Zenith Bank Plc and Analog Devices from its leak site. It has not explained why, and there is no public confirmation that either organisation reached an agreement with the group.

The claimed datasets include names, addresses, contact details, customer-service records, employment information, recruitment data, student records, case histories and other corporate material.

Organisations should audit Power Pages portals

Companies using Power Pages should immediately check whether anonymous visitors can access Dataverse tables.

Security teams should disable anonymous access to business data unless it is strictly necessary. They should also preserve logs, portal configurations and relevant records before making wider changes, as these details may help establish whether data exposure occurred.

Organisations should then identify every Power Pages portal, its owner and the Dataverse environment connected to it. Teams should test each portal as an unauthenticated visitor to confirm that sensitive records cannot be viewed or downloaded.

They should also review related systems, including Power Automate, SharePoint, Power BI, payment platforms, custom connectors and service accounts. Any credentials or API keys found in exposed data should be rotated.

The Microsoft Power Pages data breach claims highlight how a simple cloud configuration error can create major exposure without attackers needing to deploy malware or break into an internal network.


0 responses to “27M Records Allegedly Stolen Through Exposed Microsoft Power Pages”