Search TorWire

Find cybersecurity guides and research articles

Home > News > Cybersecurity > ExfilSquad Claims 382GB Data Theft from 13 Microsoft Dynamics 365 Users

ExfilSquad Claims 382GB Data Theft from 13 Microsoft Dynamics 365 Users

By: Morgan Cipher Senior Privacy Journalist

Last updated: August 19, 2026

Human Written
ExfilSquad Claims 382GB Data Theft from 13 Microsoft Dynamics 365 Users
  • A new hacker group called ExfilSquad claims it stole data from 13 organizations that use Microsoft Dynamics 365.

  • Researchers say the leak likely came from unlocked Power Pages websites, not a flaw in Dynamics 365 itself.

  • The leaked files add up to over 382 GB and touch big names like Microsoft, Frontier Airlines, and two city governments.

A new hacker group is putting pressure on companies, schools, and government offices around the world. The group calls itself ExfilSquad. It says it broke into systems that run on Microsoft Dynamics 365. Millions of people’s personal details may now sit in the wrong hands.

Security firm Fortra studied the leaked files closely. Fortra published its findings on August 13, 2026. The report backs up many of ExfilSquad’s claims. However, it also clears up how the breach likely happened.

Details of the Data Leak

ExfilSquad first showed up on July 26. At that time, it claimed to have data from 15 different organizations. Few people believed the claim at first. The group offered no real proof.

That changed fast. On July 28, ExfilSquad shared sample files as proof. Then on August 7, it released full data dumps through torrent files. Fortra says these dumps total about 382.64 GB. They contain more than 27 million records from 13 victims.

The named victims cover many fields. They include Microsoft, Allstate, and Frontier Airlines. The City of Atlanta and the City of Houston are on the list too. So is the UK Department for Education and DC Public Schools.

Each stolen file set looks different, based on the victim. Some hold customer names and emails. Others hold home addresses, phone numbers, and account details. The Houston and Atlanta files include resident service records and complaint data.

The DC Public Schools leak includes children’s names and birth dates. However, ExfilSquad chose to hold back some of that file. According to the group, it did not want to expose young children’s private details. It says it released a limited version and deleted the rest from its own servers.

Two names dropped off the list before the final release. Zenith Bank Plc and Analog Devices had appeared in the original 15 victims. Neither showed up in the August 7 leak.

How the Hackers Likely Got in

This part matters a lot. Fortra found no signs of a hacked network. It also found no sign of ransomware or stolen passwords. That rules out a classic ransomware attack.

Instead, researchers point to a simpler cause. Microsoft Power Pages lets companies build public websites tied to their internal data. Some of those websites were set up the wrong way. According to Fortra, the sites allowed anonymous visitors to read private records with no login needed.

This means anyone online could pull the data. No hacking skill was needed. No password had to be stolen. The visitor only needed to find the open door.

Fortra checked the leaked files against known Power Pages exports. The file formats and fields matched. Researchers stated that their review supports a real breach. They added that the damage likely stays limited to cloud data, not a full company takeover, since access seemed to be read-only.

Fortra also scanned the internet for more open sites like these. It found over 10,000 Power Pages sites that may allow public access right now. That number suggests many other organizations could face the same risk.

Cybersecurity Dive also reported that Fortra’s review backs the group’s central claim. Its story adds that the group first surfaced in late July.

Researchers also traced parts of the leak’s online trail. They found a server tied to the leaked files. That same server had past links to unrelated malware. This does not confirm who runs ExfilSquad. It only shows shared hosting habits some hacker groups follow.

What Organizations Should Do Now

Any company using Power Pages should act fast. Ask your IT team to check every public-facing portal today. Turn off anonymous access to any table holding private data.

Treat this as a real security event, not just a rumor. Save your site logs, permission settings, and any messages from the attackers. This record helps later if legal or insurance teams get involved.

List which portals were open and what data they held. Count the affected people where you can. Change passwords or codes tied to any exposed accounts, even though logins were not the entry point here.

Test each portal as a stranger would. Try to view data without logging in. If you succeed, so can anyone else. Fix that gap right away.

This case shows a wider lesson too. A cloud service does not need a hacked network to leak data. A single wrong setting can expose millions of records. Companies must check their public sites often, not just their internal walls.

The scale of cybercrime targeting U.S. organizations extends far beyond data leaks. U.S. Congress members have alleged that China-linked scam networks operating from Southeast Asia defraud Americans of at least $10 billion annually, warning that this fraud ecosystem has grown into a national security threat.

Share this article

About the Author

Morgan Cipher

Morgan Cipher

Senior Privacy Journalist

Morgan combines a journalist’s curiosity with a security specialist’s precision. His reporting on data breaches, privacy laws, and encryption tech has been featured in several tech publications. At TorWire, he focuses on real-world threats and how to counter them, always with an eye on what’s next in digital privacy.

Comments (0)

No comments.