ExfilSquad, a cybercrime group that emerged in July 2026, has been linked to data theft from at least 13 organizations across the U.S., UK, and Sweden by exploiting misconfigured Microsoft Power Pages portals that all...
Research answer

Create a landscape editorial hero image for this Studio Global article: What did security researchers confirm about ExfilSquad's data theft from 13 organizations, including how the group accessed the data, which. Article summary: Here is the full picture of what security researchers have confirmed about ExfilSquad's campaign.. Topic tags: general, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fake numbers, clickbait thumbnails, icons, and tiny thumbnail layouts. Make it useful as an illustrative visual, not as factua
In late July 2026, a previously unknown cybercrime group named ExfilSquad appeared on the dark web and claimed to have stolen data from roughly 15 organizations across five countries. Unlike most ransomware groups, ExfilSquad didn't deploy encryption payloads or exploit software vulnerabilities. They simply queried publicly readable cloud portals and downloaded everything that was left exposed. Now, multiple security research teams have confirmed the group's claims are authentic and have traced the campaign to a single, avoidable root cause: misconfigured Microsoft Power Pages portals .
Researchers at Fortra's FIRE team, VenariX, and Resecurity have independently reviewed data samples released by ExfilSquad. Their findings are consistent: the group did not use malware, ransomware, lateral movement, or exploit any software vulnerability .
Instead, ExfilSquad scanned for misconfigured Microsoft Power Pages portals that allowed anonymous public read access to underlying Microsoft Dataverse tables via the platform's built-in /_api Web API route . The attackers simply queried these publicly readable portals and downloaded the exposed data
. No passwords were cracked, no payloads were deployed—just a systematic scan for configuration gaps.
VenariX reviewed data samples from 11 of the 15 organizations ExfilSquad listed and found the structure and field formatting consistent with Microsoft Dataverse exports across all 11, including markers such as @odata.etag and @OData.Community.Display.V1.FormattedValue . This strongly supports the theory that a single attack method—anonymously readable Power Pages portals—was used across the entire campaign
. Microsoft has documented that assigning Dataverse table permissions to the Anonymous Users web role makes the affected data readable by anyone on the internet
.
Security researchers at Fortra have tied ExfilSquad to leaked data from at least 13 victims across multiple sectors . Resecurity reported the group claiming 13 organizations in the U.S., UK, and Sweden
. The affected sectors include government, education, financial services, manufacturing, law enforcement, insurance, retail, aviation, technology, and banking
.
Notable specific organizations named in researchers' reports:
Additional victims include municipalities, school systems, and private companies in sectors such as insurance, retail, aviation, and banking .
Important caveat: Only the PNLD breach has been formally confirmed by the victim organization . The UK Department for Education has also acknowledged a breach of two public-facing portals
. Many of the other 13 claimed victims have not yet issued public confirmations, and researchers treat the full list as "claims" rather than independently verified intrusions
. However, Fortra's FIRE team confirmed that data samples posted by ExfilSquad are authentic and correspond to real leaked data
.
By August 7, ExfilSquad had published data dumps from 13 victims via torrents, totaling 382.64 GB of leaked information .
Ransomware-free extortion is on the rise. ExfilSquad represents a growing model where criminals skip encryption entirely and rely solely on data theft and public leak threats to coerce ransom payments . The group demands payment not to decrypt files—because nothing was encrypted—but to prevent the publication of stolen data
.
Cloud misconfiguration as an attack vector. The campaign shows that attackers are shifting from exploiting software vulnerabilities to abusing configuration gaps in cloud platforms—in this case, publicly readable Microsoft Power Pages/Dynamics 365 portals that should have been access-controlled . Microsoft has noted that assigning table permissions to the anonymous user role makes data readable to anyone
. The default settings for Power Apps portals' OData feeds were previously found to expose millions of records
.
Torrent-based data distribution makes leaks irreversible. ExfilSquad distributes stolen data via BitTorrent on top of traditional dark-web leak sites, making leaked data nearly impossible to retract once it enters peer-to-peer networks . As one report noted, "once the data dumps hit the torrent network, the content can no longer be contained"
.
Mass, simultaneous victim listing overwhelms defenders. On July 26, 2026, ExfilSquad appeared from nowhere and posted roughly 15 victim organizations at once . This technique maximizes pressure on victims and overwhelms incident responders who must prioritize which breach to investigate first
.
Low technical barrier lowers the entry threshold for cybercrime. The group's method requires no exploit development, no malware, and no privileged access—simply scanning for misconfigured cloud portals that allow anonymous read access . This dramatically lowers the barrier to entry for would-be cybercriminal groups
.
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
ExfilSquad, a cybercrime group that emerged in July 2026, has been linked to data theft from at least 13 organizations across the U.S., UK, and Sweden by exploiting misconfigured Microsoft Power Pages portals that all...