27 Million Records Exposed: Hackers Target Microsoft Power Pages in Massive Data Heist

·

A massive data exfiltration campaign has been uncovered, with hackers targeting Microsoft’s Power Pages platform to steal sensitive information from over 13 organizations. The attackers, known as ExfilSquad, claim to have stolen more than 27 million records and released hundreds of gigabytes of data after their victims failed to meet an August 5th deadline. This is not a conventional ransomware attack, but rather a case of misconfigured Microsoft Power Pages sites that may have exposed data stored in Microsoft Dataverse to anonymous visitors.

The investigation by Fortra Intelligence and Research Experts (FIRE) suggests that ExfilSquad found publicly accessible Microsoft Power Pages sites connected to Dataverse. These portals are used for building external websites and allowing customers, employees, partners, or members of the public to interact with business data. However, if not properly configured, anonymous users may have access to sensitive internal datasets.

Fortra researchers obtained and analyzed samples of the stolen data, concluding that it is a valid data breach. The investigation found no evidence of encryption payloads, lateral movement through corporate networks, or a software vulnerability in Dynamics 365 itself. Instead, the focus was on misconfigured Power Pages sites allowing anonymous access to Dataverse data.

The researchers’ leading theory is that ExfilSquad exploited publicly accessible Microsoft Power Pages sites connected to Dataverse. This platform allows organizations to build external websites and portals for interacting with business data. However, if not properly configured, these portals can expose sensitive information to anyone visiting the site.

Microsoft’s documentation warns that assigning certain table permissions to anonymous users can allow anyone visiting the site to read the data. If configurations are not intact, anonymous users may have access to larger internal datasets. The researchers identified over 10,000 potential Power Pages instances accessible to the public.

The victims of this massive data exfiltration campaign span a broad range of sectors, including government, education, financial services, manufacturing, technology, aviation, and law enforcement. Among those named by ExfilSquad are Allstate, The City of Atlanta, Bonava, District of Columbia Public Schools, the UK’s Department for Education, Frontier Airlines, The City of Houston, Newcastle University, the UK Police National Legal Database, TaylorMade and Sun Day Red, Viavi Solutions, Wesco International, Zenith Bank Plc, and Analog Devices.

Two companies, Zenith Bank Plc and Analog Devices, were removed from the list. It remains unclear why those organizations disappeared or whether they reached an agreement with the attackers. The alleged City of Houston dataset alone contains around 6 million records, according to ExfilSquad’s description, while the Atlanta data allegedly contains roughly 3 million records.

Frontier Airlines is listed with approximately 2.4 million records, while TaylorMade and Sun Day Red are listed with around 2 million. The datasets described by ExfilSquad include names, addresses, contact information, customer service records, employee information, recruitment data, student information, case histories, business records, and other personal or corporate data.

The alleged DC Public Schools dataset is particularly sensitive. ExfilSquad said it censored the release, stating that they would not ‘doxx a bunch of school children’ but instead expose how incompetent DCPS is at keeping children’s information safe. The stolen information appears to come primarily from Microsoft Dynamics 365 CRM and ERP environments, with data formats strongly resembling exports from Microsoft’s Dataverse platform.

Organizations using Power Pages should first check whether their portals allow anonymous users to access Dataverse data. Security teams can use the Power Pwn module to test a specific portal for anonymous access to Dataverse tables. If exposure is found, the key step is to disable anonymous access to business data and preserve logs and portal settings.

Organizations should identify which portals and records were exposed, including any sensitive customer or employee information, and rotate credentials or API keys found in exposed records where necessary. In the following days, security teams should audit every Power Pages portal, document its owner and connected Dataverse environment, and enforce a zero-trust approach.

Users should be authenticated before accessing business data, and organizations should test their portals from the perspective of an unauthenticated visitor to make sure sensitive records cannot be viewed or downloaded. Organizations should also review connected services such as Power Automate, SharePoint, Power BI, payment systems, custom connectors, and service accounts.