Researchers Confirm ExfilSquad’s Access to Sensitive Data – Infosecurity Magazine

August 14, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: infosecurity-magazine.com

Threat Risk: High
Victim: Government, Education, and Financial institutions
Incident: Large-scale data exfiltration and extortion campaign targeting misconfigured Microsoft portals.
Impact: Exposure of 27 million records including PII and sensitive government data across 13 organizations.
Attacker: ExfilSquad
Analysis: ExfilSquad is targeting organizations with misconfigured Microsoft Power Pages portals, specifically those where the ‘Anonymous Users’ web role allows public read access. By crawling for these vulnerabilities, the group has exfiltrated over 380 GB of data from 13 different organizations. The attack highlights a systemic risk for entities using Microsoft Dataverse exports without strict permission controls.
Recommendations: Audit Microsoft Power Pages table permissions to ensure the ‘Anonymous Users’ web role is not granted read access.; Implement strict authentication and authorization checks for external-facing API endpoints.; Utilize automated scanning tools to identify and remediate exposed SaaS portals across the organization.
Source: Infosecurity Magazine

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *