A New Extortion Group Targets Microsoft Dynamics Customers

A data-extortion group calling itself ExfilSquad has published 382.64GB of data it claims to have stolen from 13 organizations that rely on Microsoft Dynamics 365. The group surfaced publicly in late July and initially claimed access to as many as 15 victims before researchers narrowed confirmed exposure down to 13 organizations spanning multiple sectors, including government entities.

What makes this incident notable isn't just the volume of data dumped, it's the method. Rather than relying on traditional ransomware or phishing to breach networks, ExfilSquad appears to have exploited misconfigured Microsoft Power Pages portals connected to Dataverse, the underlying data platform for Dynamics 365. When these portals are set up without proper access controls, they can expose sensitive records to anyone who knows where to look, no sophisticated hacking required.

How the ExfilSquad Data Leak Unfolded

Instead of the usual dark web leak site model, ExfilSquad has been distributing stolen files via torrents, a distribution method that makes the data harder to take down and easier to spread widely once it's out. This approach amplifies the damage because removing a single leak site doesn't stop the files from circulating.

The group's activity fits a pattern that has been building for months. ExfilSquad previously threatened to leak data tied to semiconductor company Analog Devices, which disclosed unauthorized access to its systems earlier this summer. That earlier case showed the group was already active and willing to pressure victims publicly. This latest 382GB release suggests the group has scaled its operation significantly, moving from single-target extortion attempts to bulk data dumps affecting more than a dozen organizations at once.

The common thread across the confirmed victims appears to be their use of Microsoft Power Pages, a low-code tool that lets organizations build external-facing websites connected to their internal business data. When these portals aren't configured with the right permission settings, data that should stay internal, customer records, case files, internal communications, can become accessible to outside parties without triggering a traditional breach alert.

Why Misconfigured Cloud Portals Keep Causing Breaches

This incident underscores a recurring theme in cloud security: the biggest risks often come not from software vulnerabilities but from configuration mistakes. Power Pages and similar low-code platforms are popular precisely because they let non-technical staff build customer portals quickly. But that same ease of use means security settings can be overlooked or set incorrectly during setup, and those mistakes can go unnoticed for months or years.

For organizations running Dynamics 365 or any Power Platform tool, this is a reminder that cloud misconfigurations are just as dangerous as unpatched software. A portal that looks fine on the surface can quietly expose sensitive data to anyone who probes it, and by the time a leak surfaces publicly, the damage is already done.

What This Means For You

If you're a customer, employee, or partner of an organization that uses Microsoft Dynamics 365 or Power Pages, this leak is worth paying attention to, even if you don't know yet whether your specific organization was affected. Data exposed through these portals can include personal information, business records, or account details that could be used for follow-up phishing attempts or identity theft.

For IT and security teams, the takeaway is more direct: audit your Power Pages configurations now rather than waiting for a breach notification. Misconfigured access controls on external-facing portals are a known and preventable weakness, and this incident shows attackers are actively scanning for them.

Actionable Takeaways

  • If your organization uses Dynamics 365 or Power Pages, review portal permission settings and confirm that only intended data is publicly accessible.
  • Monitor for breach notifications from any organization you do business with that relies on Microsoft's Power Platform tools.
  • Enable multi-factor authentication on any accounts tied to organizations that may have been affected, since leaked data can fuel targeted phishing.
  • Watch for unusual account activity or unsolicited communications referencing personal details, a common follow-up tactic after large data leaks.
  • Encourage security teams to treat cloud configuration audits as an ongoing process, not a one-time setup task.

The ExfilSquad case is a reminder that data protection increasingly hinges on how well organizations configure the cloud tools they already use, not just on defending against external hackers breaking in. Staying informed about incidents like this one is one of the simplest ways to protect your own data before it becomes part of the next leak.