Home Cyber Security News ExfilSquad Hackers Leak 382GB of Microsoft D365 Data From 13 Victims

ExfilSquad Hackers Leak 382GB of Microsoft D365 Data From 13 Victims

0
ExfilSquad Leaks D365 Data

A new data-extortion group known as ExfilSquad has leaked 382.64GB of data allegedly stolen from 13 organizations using Microsoft Dynamics 365 CRM and ERP environments.

The released archive reportedly contains around 27 million records, including personally identifiable information, customer support data, internal business records, and account-related details.

Security researchers at Fortra said the group first appeared on July 26, 2026, when it claimed to have obtained data from 15 organizations.

The claims initially lacked evidence, but ExfilSquad later published samples and then released larger data archives through torrents after an August 5 deadline passed. On August 7, the group published data linked to 13 alleged victims.

The campaign is notable because current evidence does not point to a Microsoft Dynamics 365 software vulnerability or a traditional ransomware intrusion.

Instead, researchers believe the attackers may have abused exposed Microsoft Power Pages portals that allowed anonymous users to read Dataverse data.

ExfilSquad Leaks D365 Data

Fortra’s analysis found that the leaked files appear consistent with data exported from Microsoft Dynamics 365 CRM and ERP systems.

Researchers said the available evidence indicates unauthorized access to SaaS-hosted data rather than a full compromise of each victim’s internal network.

There was no observed evidence of lateral movement, ransomware encryption, or an exploit affecting Dynamics 365 itself.

The group’s published victim list includes organizations in government, education, aviation, retail, insurance, and technology.

The alleged victims include the City of Atlanta, City of Houston, Frontier Airlines, Newcastle University, TaylorMade, Viavi Solutions, Wesco International, and the UK Department for Education.

ExfilSquad Leaks D365 Data (Source: xmcyber)

ExfilSquad also published an archive it associated with Microsoft, though public leak-page claims should not automatically be treated as independently verified breach confirmations. The exposed data varies by organization.

Examples cited in the leaked summaries include customer contact details, addresses, service requests, internal case-management records, employee information, travel and complaint records, business account data, and student-related information.

Fortra reported that a censored District of Columbia Public Schools dataset allegedly contained records for about 60,000 students, including names, dates of birth, addresses, and school-assignment details.

ExfilSquad claimed two initially named organizations, Zenith Bank Plc and Analog Devices, but neither was included in the final set of 13 published archives.

This difference highlights the need for caution when assessing threat-group statements. Extortion groups often amplify claims to pressure victims, while the precise scope and authenticity of every alleged victim may take time to establish.

The leading theory is that ExfilSquad located publicly exposed Power Pages portals with anonymous read access to Dataverse tables.

Microsoft Power Pages allows organizations to create external-facing websites connected to business data.

However, a portal can become dangerous when its permissions allow unauthenticated visitors to view data that should only be available to employees, customers, or partners, xmcyber said.

Fortra said the data formats match Dataverse exports and that attackers could have used crawling and enumeration to find misconfigured portals.

Researchers identified more than 10,000 potentially publicly accessible Power Pages instances during their investigation, underlining the scale of the exposure risk.

Detect, investigate, and respond faster with in-browser data inspection from ANY.RUN. Gain complete phishing visibility to strengthen your SOC and reduce MTTR   

NO COMMENTS

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Exit mobile version