Fortra Confirms ExfilSquad Access to Data of 13 Organizations
This digest was compiled by AI from multiple sources — links to the originals are below.

Fortra Intelligence and Research Experts confirm that the ExfilSquad extortion group accessed sensitive data from at least 13 organizations, including the City of Atlanta, the UK Department for Education and the UK Police National Legal Database. The group publishes a 382.64 GB archive of 27 million records across the victims on August 7.
Key Facts
- ExfilSquad first emerged on July 26 and claimed to have exfiltrated data from 15 organizations, but published torrents for 13 victims on August 7.
- District of Columbia Public Schools was also listed, with attackers releasing a censored version of 60,000 student records including names, dates of birth and unique student identifiers.
- Zenith Bank Plc and Analog Devices were absent from the August 7 data dumps despite appearing on the original 15-victim list.
- Fortra said the most likely attack vector was unauthorized access to Microsoft D365 CRM and ERP instances through misconfigured Microsoft Power Pages portals that allowed public read access.
- Fortra said the breach reaching only 15 victims makes a D365 vulnerability unlikely, and highlighted a Power Pages issue where the Anonymous Users web role lets anyone read table data.
Victim Exposures
ExfilSquad published torrents for 13 victims on August 7, naming the City of Atlanta, the UK Department for Education and the UK Police National Legal Database. The full archive '[victim]_exfilsquad' contains 382.64 GB and 27 million records. District of Columbia Public Schools was also listed, and the attackers released a censored version of 60,000 student records, including names, dates of birth and unique student identifiers. The attackers wrote that they would not dox school children but would expose DCPS incompetence and had shredded the original archive. Zenith Bank Plc and Analog Devices, named in the original 15-victim list, did not appear in the August 7 dumps.
Attack Vector Assessment
Fortra researchers said the breaches were limited to unauthorized access of Microsoft D365 CRM and ERP instances. Fortra's leading theory on the initial attack vector is misconfigured Microsoft Power Pages portals that allowed public read access. Fortra said victims were likely identified through crawling for misconfigured Microsoft Power Pages portals or other enumeration techniques. Because the breach reached only 15 victims rather than tens of thousands, Fortra said a D365 vulnerability is unlikely to be the source. Fortra also highlighted a known Power Pages issue in which assigning the Anonymous Users web role to a table permission lets anyone read table data via the portal API.
1 source
Fortra Confirms ExfilSquad Access to Data of 13 Organizations



