ExfilSquad Leaks 382GB of Microsoft Dynamics 365 Data From 13 Organizations
A newly identified data-extortion group known as ExfilSquad has reportedly leaked 382.64GB of data allegedly stolen from 13 organizations using Microsoft Dynamics 365 CRM and ERP environments.
The leaked information reportedly represents approximately 27 million records containing personally identifiable information (PII), customer-support records, internal business information, and account-related data.
The incident is drawing attention because the available evidence does not indicate a conventional Microsoft Dynamics 365 software vulnerability or a traditional ransomware attack.
ExfilSquad Leaks 382GB of Microsoft Dynamics
Instead, researchers believe the campaign may have exploited misconfigured Microsoft Power Pages portals that exposed Microsoft Dataverse information to unauthenticated users.
According to security researchers at Fortra, ExfilSquad first appeared on July 26, 2026, claiming that it had obtained information from 15 organizations.
The initial claims were not accompanied by sufficient evidence, but the group subsequently released samples of the alleged stolen information.
After an August 5 deadline passed, ExfilSquad reportedly published larger archives through torrent networks. On August 7, the group released data associated with 13 alleged victims.
The sequence suggests an extortion-focused operation in which attackers use public disclosures and escalating data releases to pressure organizations into responding to their demands.
Fortra’s analysis indicates that the leaked files appear consistent with information exported from Microsoft Dynamics 365 CRM and ERP environments.
However, researchers found no observed evidence of lateral movement, ransomware encryption, or exploitation of a vulnerability within the Dynamics 365 platform itself.
This distinction is technically important because the incident appears to involve unauthorized access to SaaS-hosted business data rather than a complete compromise of each victim’s internal corporate network.
Organizations could therefore face significant data exposure even when their traditional endpoint and network security controls remain uncompromised.
The alleged victim list spans multiple sectors, including government, education, aviation, retail, insurance, and technology.
Organizations named by ExfilSquad include the City of Atlanta, City of Houston, Frontier Airlines, Newcastle University, TaylorMade, Viavi Solutions, Wesco International, and the UK Department for Education.
The group also published an archive associated with Microsoft. However, threat-actor leak-site claims should not automatically be considered independently verified breach confirmations.
ExfilSquad initially named Zenith Bank Plc and Analog Devices, but those organizations were reportedly absent from the final set of 13 published archives, demonstrating why threat-intelligence claims require careful validation.
The exposed information reportedly differs between organizations and includes customer contact information, addresses, service requests, internal case-management records, employee information, travel and complaint records, business-account details, and student-related information.
One alleged District of Columbia Public Schools dataset reportedly contained information involving approximately 60,000 students, including names, dates of birth, addresses, and school-assignment information.
If authentic, datasets containing this type of information could create substantial privacy, identity-theft, fraud, and targeted-social-engineering risks for affected individuals.
The leading theory behind the campaign involves publicly accessible Microsoft Power Pages portals configured with overly permissive anonymous access to Dataverse tables.
Power Pages enables organizations to build external-facing websites that connect to business data. If portal permissions are incorrectly configured, unauthenticated visitors may potentially retrieve information that should be restricted to employees, customers, or authorized partners.
Fortra reportedly identified more than 10,000 potentially publicly accessible Power Pages instances during its investigation, highlighting the broader security risk created by cloud application misconfiguration.
The ExfilSquad campaign demonstrates that organizations must secure not only applications and networks but also the permissions connecting external-facing portals to sensitive cloud databases.
Security teams should review Power Pages configurations, disable unnecessary anonymous access, audit Dataverse table permissions, monitor unusual data enumeration, and regularly test publicly accessible applications.
The incident also reinforces the importance of continuous exposure management because a system does not need to contain a software vulnerability to become a major data-breach risk when security controls are incorrectly configured.
No Comment! Be the first one.