Threat Intelligence Brief
Curated summary with source attribution
Source: thehackernews.com
Threat Risk: Medium
Victim: UK Government and Police personnel
Incident: Unauthorized access and leak of professional contact information from the Police National Legal Database.
Impact: Increased risk of targeted phishing and social engineering attacks against UK law enforcement and judicial staff.
Attacker: ExfilSquad
Analysis: The breach likely stems from misconfigured Microsoft Power Pages permissions, which may have granted anonymous access to underlying Dataverse tables. While sensitive criminal data remained secure, the exposure of professional email addresses enables highly convincing, targeted phishing campaigns. This incident highlights a systemic risk where public-facing cloud portals are inadvertently left open to unauthenticated queries.
Recommendations: Review and restrict ‘Anonymous Users’ permissions within Microsoft Power Pages and Dataverse environments.; Audit all public-facing web APIs and legacy OData feeds to ensure strict authentication is enforced.; Provide targeted social engineering awareness training to high-profile government and law enforcement staff.
Source: The Hacker News
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source