Data Security

ExfilSquad data extortion group linked to 13 victim data leaks

Laptop Screen Warning Alert: Cyber Attack, Virus, Malware, Spyware, System Hacked

As reported by Infosecurity Magazine, the ExfilSquad data extortion group has been linked to leaked data from at least 13 victims across various sectors, including government, education, financial services, and manufacturing. This analysis stems from Fortra Intelligence and Research Experts (FIRE), who have reviewed data samples publicly released by the group and confirmed the validity of their claims.

ExfilSquad, which emerged on July 26, initially claimed to have exfiltrated data from 15 organizations. By August 7, data dumps from 13 victims were published via torrents, totaling 382.64 GB and approximately 27 million records. Notable victims included the City of Atlanta, the UK Department for Education, and the UK Police National Legal Database. The group also targeted District of Columbia Public Schools (DCPS), releasing a censored version of 60,000 student records containing PII.

Researchers theorize that the breaches resulted from unauthorized access to Microsoft D365 CRM and ERP instances, likely enabled by misconfigured Microsoft Power Pages portals that allowed public read access. This vulnerability, where an Anonymous Users web role assigned to a table permission grants anyone visiting the site read access, is a known issue. Attackers likely identified victims by crawling for these exposed portals.

Source: Infosecurity Magazine

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds