Back to Exposure Report
Cross-Sector / Cloud MisconfigurationJuly 26, 2026Global

ExfilSquad

No malware. No lateral movement. No exploited vulnerability. Fifteen organizations listed in a single day — and the working theory is that the front door was simply left open.

Personally identifiable informationEmployee & customer contact dataPassword hashesPortal and account identitiesInternal service ticketsAccess rightsBusiness leads
1

What happened?

A previously unknown data-extortion group calling itself ExfilSquad surfaced with a Tor-hosted leak site and published its entire initial victim roster — 15 claims — within a single day on July 26, 2026.

The named organizations: Microsoft, Allstate, Frontier Airlines, TaylorMade and Sun Day Red, Analog Devices, VIAVI Solutions, Wesco International, Bonava, Zenith Bank, Newcastle University, the District of Columbia Public Schools, the UK Department for Education, the Police National Legal Database, the City of Atlanta, and the City of Houston. No forensic detail, data sample, or independent confirmation has accompanied any of the claims.

2

What data was actually inside?

For Microsoft, ExfilSquad claims roughly 8 million records including personally identifiable information, employee and customer contact information, identification data, password hashes, portal and account identities, corporate information, business leads, facility management data, internal service tickets, and access rights. For Allstate, the group claims more than 657,000 records and 15.1 gigabytes.

Treat these as claims. None has been substantiated with a sample. What makes the Microsoft list worth reading anyway is its shape: service tickets, facility management data, portal identities, and access rights are not the contents of a customer database. They are the contents of an internal-facing web portal — which is consistent with the delivery mechanism researchers have identified.

3

Who gets hurt and how?

Look at who is on the list. The District of Columbia Public Schools and the UK Department for Education hold records on children. The Police National Legal Database serves UK law enforcement. Frontier Airlines separately confirmed on July 9, 2026 that an unauthorized party accessed a data storage account containing personal information — weeks before ExfilSquad's listing.

If the claims hold, the harm is uneven and specific. Password hashes support offline cracking and credential stuffing elsewhere. Access rights and portal identities support follow-on intrusion, because they describe who can reach what. Internal service tickets are free-text and routinely contain credentials, configuration details, and personal circumstances that no field on a form would ever capture. For the education entities, the affected data subjects are minors who cannot monitor their own credit.

4

What did they think they were doing right?

Every organization on this list runs a security program. Microsoft publishes threat intelligence the rest of the industry consumes. These are not soft targets by any conventional measure, and their perimeter defenses, endpoint tooling, and detection capabilities were almost certainly working exactly as designed.

They were designed for the wrong event. Researchers at VenariX have not identified evidence of ransomware deployment, malware use, lateral movement, or exploitation of a software vulnerability. The available evidence instead points to anonymous users being granted overly broad access to Dataverse records through public Microsoft Power Pages portals. There was no intrusion to detect. Every request was an authorized read from an unauthenticated visitor, which is what the portal was configured to permit.

5

What did they not know about their own data?

Low-code platforms invert the normal control model. A Power Pages portal can be stood up by a business team without a procurement cycle, a security review, or an entry in the application inventory — that is the entire value proposition. The portal is then pointed at Dataverse tables, and the table permissions determine what an anonymous visitor can read.

Nobody in the security organization necessarily knows the portal exists. Nobody re-checks which tables it was wired to after the initial build. The person who configured it has often changed roles. The result is a public endpoint, backed by production data, that appears on no asset list and in no data map — and whose exposure is invisible to vulnerability scanning, because there is no vulnerability.

Fifteen unrelated organizations, in one day, across government, education, aviation, banking, insurance, and manufacturing. That is not a sophisticated campaign. It is one blind spot, found fifteen times, by someone who thought to look.

If you use cloud storage, do you know what sensitive data lives in your buckets and blobs? Or would you find out the same way they did?

6

What does attribution look like the morning after?

This scenario is materially harder to investigate than a ransomware event. There is no encryption timestamp, no malware sample, no lateral movement path, no obvious point of compromise. To determine whether a claim is true, an organization has to identify every Power Pages portal it operates, enumerate the Dataverse tables each was permitted to read, and reconstruct from web logs which records an anonymous session actually retrieved — assuming that logging was enabled at sufficient granularity, which for a portal nobody knew about is not a safe assumption.

The regulatory exposure spans jurisdictions with different regimes. The UK Department for Education and the Police National Legal Database fall under UK GDPR, with a 72-hour notification requirement to the ICO from awareness of a personal data breach. DC Public Schools engages FERPA and US state law. Allstate faces state insurance regulators alongside breach statutes; the company is investigating. Fifteen organizations are now each running this analysis independently, and none can see the others' findings.

7

What would have changed the outcome?

A current inventory of every public-facing portal and the exact records reachable behind each one — the one artifact that makes a misconfiguration visible before someone else finds it.

There is nothing to patch here. No vulnerability was exploited, no signature would have fired, and no amount of endpoint tooling would have changed the outcome, because the data left through a door that was configured to be open. The only defense against exposure-by-configuration is knowing what your systems expose — which requires an inventory that covers the applications your business teams built themselves, not just the ones IT procured. Fifteen organizations are learning that this week. Compare the Chick-fil-A credential stuffing disclosure, another incident with no vulnerability and no perimeter to defend.

The organizations ExfilSquad listed found out the hard way.

Your team could spend the next 6 months rebuilding systems, notifying customers, and answering legal questions. Or you could spend 24 hours finding out what's actually at risk.