Researchers Confirm Data-Extortion Group Breach Claims

0
4

Key Takeaways

  • The extortion group ExfilSquad claims to have stolen tens of gigabytes of data from roughly 15 public‑ and private‑sector organizations, including city governments, universities, airlines, and major corporations.
  • Independent analysis by Fortra supports the claim, linking the exposure to misconfigured Microsoft Power Page portals that unintentionally granted public read access to underlying Dynamics 365 databases.
  • No evidence of a software‑vulnerability exploit or ransomware deployment was found; the breach resulted from configuration errors rather than code flaws.
  • Alleged victims comprise the city of Atlanta, Allstate, the U.K. Department for Education, Frontier Airlines, and Microsoft, with reported data sizes ranging from a few hundred megabytes to over 130 GB.
  • Affected entities have not issued immediate public statements, leaving the full scope and authenticity of the leaked data under active investigation.
  • The incident highlights the persistent danger of cloud‑service misconfigurations and stresses the need for continuous configuration monitoring, least‑privilege access controls, and rapid remediation.

Overview of ExfilSquad’s Claims
On July 26, a threat actor identifying itself as ExfilSquad posted on underground forums claiming to have exfiltrated sensitive data from a diverse set of targets, including municipal governments, universities, a large public‑school system, and several private corporations. The group asserted that it had obtained customer records, internal communications, financial details, and other proprietary information, and it promised to release proof of the breach to validate its allegations. Initially met with skepticism by the security community, ExfilSquad later published sample files purportedly taken from the compromised entities, prompting researchers to investigate the veracity of the claims. The samples included CSV‑style extracts that appeared to contain personally identifiable information (PII) such as names, email addresses, and transaction identifiers, which added weight to the group’s assertions and encouraged a deeper technical look into how the data could have been obtained.

Verification by Security Researchers
Fortra’s threat‑intelligence team released a detailed report on Thursday that lent credibility to ExfilSquad’s assertions. By analyzing the leaked samples and cross‑referencing them with publicly available information, Fortra concluded that the data appeared consistent with the purported victims. The researchers emphasized that they did not discover any novel software vulnerability being exploited; instead, the breach seemed to arise from a configuration oversight that allowed unauthorized retrieval of data stored in Microsoft’s cloud services. Fortra’s analysts also noted that the leaked files contained internal identifiers that matched known schemas for Dynamics 365 tables, further supporting the hypothesis that the data originated from misconfigured SaaS components rather than from a bespoke exploit.

Technical Details: Misconfigured Power Page Portals
The investigation traced the exposure to misconfigured Microsoft Power Page portals—a software‑as‑a‑service offering used to build public‑facing websites and applications. When these portals are improperly secured, they can inadvertently expose underlying Microsoft Dynamics 365 (D365) databases to the internet. In the observed cases, the portals were set to allow public read access, enabling anyone with the correct URL to query and download tables containing personal and organizational data. This misconfiguration effectively turned a benign web‑front end into a data‑leak conduit without requiring any code‑level exploit. Researchers pointed out that the default sharing settings for Power Pages can be overridden during deployment, and if administrators neglect to lock down anonymous access, the portal becomes a gateway to the back‑end data store. The lack of multifactor authentication for the service accounts used by the portals further amplified the risk, allowing attackers to harvest data through simple HTTP GET requests.

Reported Victims and Data Volumes
ExfilSquad’s statement listed several high‑profile targets along with approximate data sizes: the city of Atlanta allegedly yielded more than 36 GB encompassing roughly three million records; Allstate’s leak was said to exceed 15 GB with about 657,000 records; the U.K. Department for Education contributed 440 MB and around 600,000 records; Frontier Airlines accounted for 43 GB and approximately 2.4 million records; and Microsoft itself was claimed to have lost 130 GB containing roughly eight million records. These figures, while impressive, remain unverified pending formal confirmation from the affected entities. Security analysts cautioned that the reported sizes could be inflated or deflated depending on the compression and deduplication methods used by the threat actors, and that independent verification would require access to the original source systems or trusted third‑party attestations.

Responses from Affected Organizations
As of the time of reporting, representatives from Microsoft, Frontier Airlines, the city of Atlanta, and Allstate had not responded to requests for comment regarding the alleged breach. The lack of immediate public acknowledgment does not necessarily indicate denial; organizations often undertake internal investigations before issuing statements, especially when the legitimacy of leaked data is still under scrutiny. Security analysts advise stakeholders to monitor official channels for updates and to consider precautionary measures such as password resets, monitoring for suspicious login attempts, and reviewing any exposed credentials for potential misuse. Some industry observers noted that large enterprises may be coordinating with law‑enforcement and regulatory bodies before making public disclosures, which could explain the delayed communication.

Implications for Cybersecurity Practices
The ExfilSquad incident serves as a stark reminder that cloud‑service misconfigurations remain a leading cause of data exposure. Even when software is free of vulnerabilities, improper permission settings can inadvertently open the door to data theft. Organizations utilizing Power Pages, Dynamics 365, or similar SaaS platforms should enforce strict configuration baselines, conduct regular automated scans for overly permissive sharing settings, and adopt the principle of least privilege for all service accounts. Additionally, implementing continuous monitoring and alerting for anomalous data‑access patterns can help detect exfiltration attempts early, reducing the potential impact of similar episodes. Security teams should also consider implementing network‑level controls, such as restricting outbound traffic from web‑front‑end services to known legitimate endpoints, and employing data‑loss‑prevention (DLP) solutions that can flag large‑volume exports of sensitive tables.

Conclusion and Recommendations
While the full authenticity of ExfilSquad’s leaked data set awaits confirmation, the corroborating evidence from Fortra underscores a realistic scenario in which misconfigured Power Page portals facilitated unauthorized access to substantial volumes of sensitive information. Organizations should treat this event as a catalyst to review and harden their cloud‑service configurations, invest in automated security posture management tools, and maintain robust incident‑response readiness. By addressing configuration gaps proactively, businesses and governmental bodies can significantly lower the risk of falling victim to data‑extortion schemes that exploit administrative oversights rather than sophisticated code exploits. Regular penetration testing, configuration‑as‑code reviews, and mandatory security‑awareness training for administrators responsible for SaaS deployments are essential steps toward building a resilient defense against future misconfiguration‑driven breaches.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here