Security researchers are backing claims by a newly emergent data-extortion group that it has exfiltrated sensitive data from about 15 companies, governments and other organizations.
A threat group called ExfilSquad claimed on July 26 to have exfiltrated customer records and other information from a number of city governments and universities, a major public school system and private companies. After being met with skepticism, the threat actor later released samples of the allegedly stolen information.
Researchers at Fortra released a report Thursday that corroborates ExfilSquad’s breach claims. The leaked data appears to be related to misconfigured Microsoft Power Page portals, a software-as-a-service platform that is used to create public-facing business websites. The misconfiguration enabled unauthorized access to Microsoft D365, according to researchers, which led to public read access.
The initial claims were previously disclosed in a July report by security firm Veranix. Researchers did not find any evidence of a vulnerability being exploited or ransomware being deployed.
The threat group claims to possess data from a number of organizations, including the following:
The city of Atlanta, more than 36 GB, including 3 million records; Allstate, more than 15 GB, including 657,000 records; U.K. Department for Education, 440 MB, 600,000 records; Frontier Airlines, 43 GB, including 2.4 million records; and Microsoft, 130 GB, including 8 million records.
Representatives for Microsoft, Frontier, Atlanta and Allstate were not immediately available for comment.