ExfilSquad Leaked Sensitive Data from 13 Organizations
Cybersecurity researchers have confirmed that the data extortion group ExfilSquad accessed sensitive data from 13 organizations, including government, education, and financial sectors. The data breach, totaling over 382 GB, is believed to have originated from misconfigured Microsoft services.
What Happened
The cybersecurity world has been shaken by the activities of a new data extortion group calling itself ExfilSquad. A new analysis conducted by Fortra Intelligence and Research Experts (FIRE) has confirmed that the group's claims are not empty, and they have successfully compromised data from at least 13 organizations, including government agencies, educational institutions, and financial entities. The group first emerged on July 26, claiming to have exfiltrated data from a total of 15 organizations.
Events took a new turn on August 7, when the group publicly released the data from 13 of these organizations via torrents. ExfilSquad stated that their reason for this action was that the victim organizations "did not meet the agreements." This indicates that the group had demanded a ransom or some other form of financial payment, but their demands were not met. FIRE researchers meticulously examined the leaked data samples and concluded that the group's claims of having access to sensitive information were correct. This confirmation highlights the seriousness of the attack and the risk it poses to the affected institutions.
The Exfiltrated Data
The size and content of the data archive released by ExfilSquad reveal the immense scale of the attack. The full archives, labeled in the format "[victim_name]_exfilsquad," constitute a massive data dump totaling 382.64 GB. According to researchers, this enormous archive contains a total of 27 million records from the 13 victims. While the nature of the leaked data varies from one organization to another, it generally includes sensitive and personal information.
The District of Columbia Public Schools (DCPS) leak is particularly one of the most concerning aspects of the incident. In a note published with the leak, the attackers stated, "We are not going to dox a bunch of school children, but we are going to expose how incompetent DCPS is at keeping children as young as six's information safe." Accordingly, they claimed to have released a censored version of the leak and to have entirely shredded the original files from their servers. Despite this, even the censored data contains personally identifiable information (PII) for 60,000 students, including names, dates of birth, and unique student identifiers. This is a serious security breach that could leave children vulnerable to identity theft and other forms of fraud.
How Did the Attack Happen
Fortra researchers state that the data breaches are most likely limited to unauthorized access of Microsoft Dynamics 365 Customer Relationship Management (CRM) and Enterprise Resource Planning (ERP) instances. These types of systems house an organization's most critical information, such as customer data, financial records, and operational processes.
The leading theory on the initial point of entry focuses on configuration errors in the Microsoft Power Pages services used by the institutions. Power Pages is a platform that allows organizations to create websites and applications for external users (customers, partners). If these pages are not configured correctly, authentication and authorization controls can be weak. This weakness may have allowed attackers to gain unauthorized access to the D365 databases that should have been protected. Researchers believe that ExfilSquad exploited these configuration flaws to exfiltrate the data. Investigations into the precise technical details of the attack and other potential vulnerabilities are ongoing.
Who Was Affected
The 13 organizations whose data was leaked by ExfilSquad and confirmed by FIRE are notable for being from different sectors and geographical locations. This suggests that the group does not target a specific industry but rather attacks wherever it finds a vulnerability. The confirmed victims include:
- City of Atlanta (atlantaga.gov): Municipal data from a major U.S. metropolis.
- UK Department for Education (education.gov.uk): The government body responsible for education policies and data in the United Kingdom.
- UK Police National Legal Database: A system containing critical legal information for law enforcement.
- District of Columbia Public Schools (DCPS): Sensitive data belonging to students in the U.S. capital.
Two organizations that were on the group's initial list of 15 targets, Zenith Bank Plc and Analog Devices, did not have their data leaked on August 7. It is not yet known why their data was not published or if they reached a separate agreement with the group.
What You Can Do
A large-scale data breach like this poses significant risks for both individuals and organizations. The following steps can be taken:
- For Organizations: It is critical for all organizations using Microsoft D365 and Power Pages to treat this incident as a warning. The security configurations of all externally facing Power Pages portals should be reviewed immediately. Data access permissions must be checked to ensure anonymous users cannot access sensitive information, and the principle of least privilege should be rigorously applied.
- For Individuals: If you have a relationship with any of the affected institutions (e.g., you are a resident of Atlanta or a parent of a DCPS student), you need to be vigilant. Your leaked personal information could be used in phishing attacks against you. Be wary of suspicious emails, text messages, or phone calls that refer to your name, date of birth, or other personal details. It is recommended to change the passwords for your relevant accounts and enable two-factor authentication (2FA) wherever possible.
What the Company Is Saying
As of the publication date of this news, August 14, 2026, none of the 13 confirmed affected organizations have issued a comprehensive public statement on the matter. Microsoft, the technology provider at the center of the attack, has also not yet commented on the incident. For now, information regarding the technical details and impact of the event is limited to the analysis published by Fortra (FIRE) researchers. The affected institutions are expected to complete their internal investigations and inform the public and affected individuals in the coming days.
Source
https://www.infosecurity-magazine.com/news/exfilsquads-13-organizations/
This content was generated with AI assistance through our Argus Flow application. We are continuously working to improve Argus Flow; if you encounter any issues such as translation errors, incorrect sources, or unverified information, you can report them using the button below. We appreciate your feedback.