Skip to content

27 million records stolen from Microsoft Power Pages portals

Bottom line: Misconfigured access permissions on Microsoft Power Pages portals, not a vulnerability in Dynamics 365, allegedly enabled the exfiltration of 27 million records from 13 organizations.

The group ExfilSquad claims to have exfiltrated data from 13 organizations via misconfigured access permissions on Microsoft Power Pages portals. According to Fortra’s analyses, the affected systems are not the corporate networks themselves, but publicly accessible SaaS portals with incorrectly set permissions.

The group ExfilSquad first appeared on July 26 with its own leak site on the darknet, initially claiming to have compromised 15 organizations without providing evidence. Two days later, it published initial data samples, which were analyzed by Fortra Intelligence and Research Experts. The researchers assume an actual data leak occurred, but not a full compromise of the respective corporate networks, as is typical in classic ransomware attacks. The affected data predominantly originates from Microsoft Dynamics 365 CRM and ERP environments in a format consistent with a typical export from the Dataverse platform. The researchers found no evidence of system encryption, lateral movement within the network, or a specific software vulnerability in Dynamics 365.

Fortra identifies publicly accessible Power Pages portals — through which organizations communicate with customers, employees, partners, or the public — as the most likely cause. Since some data on these portals is deliberately made accessible to unauthenticated visitors while other data is not, faulty permission configuration can result in significantly more internal data being publicly viewable than intended. As part of its own investigation, Fortra identified more than 10,000 publicly accessible Power Pages instances. By August 7, ExfilSquad had published torrent files containing alleged data from 13 organizations spanning a broad range of industries, including government agencies, educational institutions, financial services providers, the aviation sector, and law enforcement agencies. Among those named are insurer Allstate, the City of Atlanta, District of Columbia Public Schools, the UK Department for Education, Frontier Airlines, the City of Houston, Newcastle University, and a UK police database. According to the group’s claims, the Houston dataset comprises around 6 million entries and the Atlanta dataset around 3 million, including names, addresses, contact details, customer service records, employee and applicant data, and student data.

The case is relevant for CISOs because the root cause lies not in a product vulnerability but in the configuration of low-code/no-code portals, which are frequently set up by business departments outside of traditional IT governance processes. In many organizations, the inventory of Power Pages instances is not fully documented, allowing permission errors to go undetected until data has already become publicly accessible.

Organizations using Power Pages should first check whether their portals grant anonymous users access to Dataverse data, for example using the auditing tool Power Pwn. If exposure is detected, anonymous access to business data should be disabled immediately, and logs and portal settings should be preserved. Affected organizations should then determine exactly which portals and datasets were exposed, rotate credentials and API keys where necessary, document all Power Pages portals along with their owners and associated Dataverse environments, and transition to a zero-trust approach requiring mandatory authentication before any access to business data. It is also advisable to review connected services such as Power Automate, SharePoint, Power BI, payment systems, as well as custom-built connectors and service accounts.


Source: www.it-daily.net · Published August 20, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on:
Tags: