27M records allegedly stolen via misconfigured Microsoft portals​ | Cybernews

August 19, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: cybernews.com

Threat Risk: High
Victim: Government agencies, educational institutions, and global corporations
Incident: Massive data exfiltration targeting misconfigured Microsoft Power Pages portals.
Impact: Exposure of 27 million sensitive personal, employee, and business records.
Attacker: ExfilSquad
Analysis: The threat actor, ExfilSquad, exploited overly permissive anonymous access settings within Microsoft Power Pages and Dataverse. Unlike traditional ransomware, this campaign focuses on SaaS data exfiltration without requiring deep network penetration or software vulnerabilities. The attack demonstrates how basic cloud misconfigurations can result in massive data exposure.
Recommendations: Audit all Microsoft Power Pages portals to disable unnecessary anonymous data access.; Enforce strict authentication and authorization policies for Microsoft Dataverse.; Review connected services and service accounts for excessive permissions.
Source: Cybernews

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *