Researchers confirm breach claims by data-extortion group
A newly emerged data-extortion group, ExfilSquad, claimed on July 26 to have stolen sensitive data from about 15 organizations. After initial skepticism, the group released samples, and Fortra's Thursday report confirms the breach, attributing it to misconfigured Microsoft Power Pages portals.

Security researchers are backing claims by a newly emergent data-extortion group that it has exfiltrated sensitive data from about 15 companies, governments and other organizations.
A threat group called ExfilSquad claimed on July 26 to have exfiltrated customer records and other information from a number of city governments and universities, a major public school system and private companies. After being met with skepticism, the threat actor later released samples of the allegedly stolen information.
Researchers at Fortra released a report Thursday that corroborates ExfilSquad’s breach claims. The leaked data appears to be related to misconfigured Microsoft Power Page portals, a software-as-a-service platform that is used to create public-facing business websites. The misconfiguration enabled unauthorized access to Microsoft D365, according to researchers, which led to public read access.
The initial claims were previously disclosed in a July report by security firm Veranix. Researchers did not find any evidence of a vulnerability being exploited or ransomware being deployed.
The threat group claims to possess data from a number of organizations, including the following:
The city of Atlanta, more than 36 GB, including 3 million records; Allstate, more than 15 GB, including 657,000 records; U.K. Department for Education, 440 MB, 600,000 records; Frontier Airlines, 43 GB, including 2.4 million records; and Microsoft, 130 GB, including 8 million records.
Representatives for Microsoft, Frontier, Atlanta and Allstate were not immediately available for comment.