A Massive Exposure Tied to Misconfigured Portals

A new investigation has revealed that hackers may have accessed as many as 27 million records from 13 organizations by exploiting exposed Microsoft Power Pages portals and the Dataverse data connected to them. The incident, reported by Cybernews, highlights how a widely used low-code platform for building customer-facing websites can become a serious liability when access controls aren't configured correctly.

Microsoft Power Pages lets businesses and government agencies quickly spin up external-facing websites, things like customer portals, application forms, or self-service dashboards, without writing extensive custom code. These portals typically pull data directly from Dataverse, Microsoft's underlying data storage service that often holds sensitive information such as customer records, applications, or internal business data. When permissions on these portals aren't locked down properly, that connection between a public-facing website and a private data store can turn into an open door.

How a Convenience Feature Becomes a Risk

The appeal of Power Pages is exactly what makes it risky if left unchecked: it's designed for speed and accessibility. Organizations can launch a functional web portal in a fraction of the time it would take to build one from scratch, but that speed can come at the cost of thorough security review. If access permissions on tables, lists, or forms within a Power Pages site are set too broadly, unauthenticated visitors, or attackers scanning for exposed endpoints, may be able to query and pull data that was never meant to be public.

This is a familiar pattern in enterprise software incidents. Attackers don't always need to breach a network directly or exploit a novel vulnerability; sometimes they simply find systems that were never properly locked down in the first place. The result can be just as damaging as a traditional breach, even though no complex hacking technique was involved. The Estรฉe Lauder data breach linked to Oracle EBS exploitation is another example of how vulnerabilities or misconfigurations in enterprise platforms, rather than sophisticated novel attacks, can lead to large-scale data exposure. In both cases, the underlying software wasn't necessarily broken, but the way it was deployed or secured created the opening attackers needed.

Why Scale and Trust Are the Real Concerns

What makes this Microsoft Power Pages breach notable isn't a single dramatic hack, it's the scale: 27 million records across 13 different organizations. That breadth suggests a systemic issue with how many organizations configure their Power Pages deployments, rather than an isolated mistake by one company. When a platform is used across thousands of businesses and government bodies, even a modest percentage of misconfigured instances can add up to millions of exposed records.

For the organizations involved, this kind of exposure erodes the trust that customers and citizens place in them when submitting personal information through official portals. For everyday users, the risk is less about any single incident and more about the fact that sensitive data submitted through seemingly official channels isn't guaranteed to be protected simply because it sits on a reputable company's infrastructure. Security depends heavily on how well individual organizations configure the tools they rely on, not just on the reputation of the platform provider.

What This Means For You

If you've submitted information through a business or government portal built on Microsoft Power Pages, there's currently no way to know from the outside whether your specific data was among the records exposed. The responsibility for securing that data rests with the organizations running these portals, not with individual users. That said, this incident is a good reminder to stay alert to how your personal information is collected and stored online, and to watch for any breach notifications from services you use.

Organizations using Power Pages or similar low-code platforms should treat this as a wake-up call to audit their access permissions, table-level security, and public-facing forms. A quick review of who can query what data, and whether authentication is properly enforced, can prevent this kind of exposure before it happens.

Actionable Takeaways

  • If you've interacted with a portal built on Microsoft Power Pages, keep an eye out for breach notifications from that organization.
  • Use unique passwords and enable multi-factor authentication wherever accounts tied to sensitive personal data are involved.
  • Be cautious about how much personal information you submit through online forms, even ones that appear official.
  • If you manage a Power Pages deployment, review table permissions, portal authentication settings, and Dataverse access controls immediately.

The Microsoft Power Pages breach is a clear signal that convenience-driven platforms need just as much security scrutiny as traditional custom-built systems. As more organizations adopt low-code tools to move faster, ensuring proper configuration will be essential to keeping the data behind them safe.