Microsoft and City of Atlanta: Misconfigured Microsoft Power Pages Likely Exposed 27 Million Records to ExfilSquad

Microsoft and City of Atlanta: Misconfigured Microsoft Power Pages Likely Exposed 27 Million Records to ExfilSquad

Microsoft Power Pages Misconfigurations Expose 27 Million Records in Mass Data Leak

A suspected misconfiguration in Microsoft Power Pages has led to the exposure of 27 million records across 13 organizations, after the data-extortion group ExfilSquad published 382.64 GB of stolen data via torrent on August 7. Researchers from Fortra’s Intelligence and Research Experts (FIRE) determined that the breach stemmed from publicly readable Microsoft Dataverse tables not a zero-day exploit, ransomware, or traditional network intrusion.

The incident highlights a critical cloud-security risk: overly permissive anonymous access settings in Power Pages, a tool designed to create external-facing web portals connected to Microsoft Dynamics 365 CRM and ERP environments. The leading hypothesis suggests that affected portals granted the Anonymous Users web role read access to sensitive Dataverse tables, allowing unauthenticated visitors to retrieve records via exposed API endpoints.

Unlike conventional breaches, ExfilSquad did not rely on malware, credential theft, or software vulnerabilities instead, the group exploited legitimate but misconfigured SaaS features to harvest data at scale. The exposed records included personally identifiable information (PII), CRM data, student records (names, birth dates, unique identifiers), and government service records, posing risks for spear-phishing, identity fraud, and follow-on attacks.

Reported victims span government and education sectors, including the City of Atlanta, the UK Department for Education, and District of Columbia Public Schools. The incident underscores a broader trend: cloud data exposure can be automated and mass-harvested once a portal’s API is publicly accessible, even without internal network compromise.

Security teams are advised to audit Power Pages deployments, removing the Anonymous Users role from tables unless explicitly required for public access. Where anonymous access is necessary, permissions should be narrowly scoped, and API responses should be tested from unauthenticated sessions to prevent unintended data leaks. Microsoft has since restricted wildcard API configurations for certain system tables to mitigate such risks.

The breach serves as a reminder that identity and authorization misconfigurations can turn a customer portal into an open data-export interface, exposing organizations to significant privacy and fraud risks.

Source: https://gbhackers.com/misconfigured-microsoft-power-pages/

Microsoft Power Platform cybersecurity rating report: https://www.rankiteo.com/company/microsoft-power-platform

Federal Reserve Bank of Atlanta cybersecurity rating report: https://www.rankiteo.com/company/atlantafed

"id": "MICATL1786962683",
"linkid": "microsoft-power-platform, atlantafed",
"type": "Vulnerability",
"date": "8/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Public Sector',
                        'location': 'United States',
                        'name': 'City of Atlanta',
                        'type': 'Government'},
                       {'industry': 'Education/Public Sector',
                        'location': 'United Kingdom',
                        'name': 'UK Department for Education',
                        'type': 'Government'},
                       {'industry': 'Education',
                        'location': 'United States',
                        'name': 'District of Columbia Public Schools',
                        'type': 'Education'}],
 'attack_vector': 'Misconfiguration',
 'data_breach': {'data_exfiltration': '382.64 GB published via torrent',
                 'number_of_records_exposed': '27 million',
                 'personally_identifiable_information': ['Names',
                                                         'Birth dates',
                                                         'Unique identifiers'],
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Personally identifiable '
                                              'information (PII)',
                                              'CRM data',
                                              'Student records',
                                              'Government service records']},
 'date_publicly_disclosed': '2024-08-07',
 'description': 'A suspected misconfiguration in Microsoft Power Pages led to '
                'the exposure of 27 million records across 13 organizations '
                'after the data-extortion group ExfilSquad published 382.64 GB '
                'of stolen data via torrent on August 7. The breach stemmed '
                'from publicly readable Microsoft Dataverse tables due to '
                'overly permissive anonymous access settings in Power Pages, a '
                'tool for creating external-facing web portals connected to '
                'Microsoft Dynamics 365 CRM and ERP environments. The incident '
                'highlights critical cloud-security risks where legitimate but '
                'misconfigured SaaS features were exploited to harvest data at '
                'scale without malware, credential theft, or software '
                'vulnerabilities.',
 'impact': {'brand_reputation_impact': 'Significant',
            'data_compromised': '27 million records',
            'identity_theft_risk': 'High',
            'systems_affected': 'Microsoft Power Pages, Microsoft Dataverse, '
                                'Microsoft Dynamics 365 CRM and ERP '
                                'environments'},
 'initial_access_broker': {'entry_point': 'Misconfigured Power Pages portals '
                                          'with Anonymous Users web role'},
 'lessons_learned': 'Cloud data exposure can be automated and mass-harvested '
                    'once a portal’s API is publicly accessible, even without '
                    'internal network compromise. Identity and authorization '
                    'misconfigurations can turn a customer portal into an open '
                    'data-export interface, exposing organizations to '
                    'significant privacy and fraud risks.',
 'motivation': 'Data extortion',
 'post_incident_analysis': {'corrective_actions': 'Microsoft restricted '
                                                  'wildcard API configurations '
                                                  'for certain system tables '
                                                  'to mitigate risks',
                            'root_causes': 'Overly permissive anonymous access '
                                           'settings in Microsoft Power Pages, '
                                           'granting the Anonymous Users web '
                                           'role read access to sensitive '
                                           'Dataverse tables'},
 'ransomware': {'data_exfiltration': 'Yes'},
 'recommendations': 'Audit Power Pages deployments, remove the Anonymous Users '
                    'role from tables unless explicitly required for public '
                    'access. Where anonymous access is necessary, permissions '
                    'should be narrowly scoped, and API responses should be '
                    'tested from unauthenticated sessions to prevent '
                    'unintended data leaks.',
 'references': [{'source': 'Fortra’s Intelligence and Research Experts '
                           '(FIRE)'}],
 'response': {'remediation_measures': 'Audit Power Pages deployments, remove '
                                      'Anonymous Users role from tables unless '
                                      'explicitly required, narrowly scope '
                                      'permissions, test API responses from '
                                      'unauthenticated sessions',
              'third_party_assistance': 'Fortra’s Intelligence and Research '
                                        'Experts (FIRE)'},
 'threat_actor': 'ExfilSquad',
 'title': 'Microsoft Power Pages Misconfigurations Expose 27 Million Records '
          'in Mass Data Leak',
 'type': 'Data Exposure',
 'vulnerability_exploited': 'Publicly readable Microsoft Dataverse tables due '
                            'to overly permissive anonymous access settings'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.