ExfilSquad Data Extortion Campaign Targets Misconfigured Power Pages
A data extortion campaign has exposed millions of records from multiple organizations after attackers targeted misconfigured Microsoft Power Pages deployments.
The activity appears to have relied on anonymous access permissions that allowed hackers to enumerate and export records without exploiting a software vulnerability.
Organizations using Power Pages are advised to review their settings, including anonymous access permissions, Dataverse table access, exposed API endpoints, and public-facing portal configurations, to identify and reduce unintended data exposure.