Menu
Browse

Cyber Incident Victim: District of Columbia Public Schools

Date

Aug 2026

Location

United States of America

Status

Unknown

Updated

2026-08-17 06:24

Timeline
Occurred
Undetermined
Discovered
Undetermined
Disclosed
Aug 2026
Resolved
Pending
Summary

Researchers confirmed that the extortion group ExfilSquad obtained and leaked sensitive data from thirteen organizations, including District of Columbia Public Schools, after exploiting misconfigured Microsoft Power Page portals that granted public read access to underlying Dataverse tables. The group released a censored version of the leak, stating it would not expose children directly but would highlight the district’s failure to protect student information, and claimed to have destroyed the original files. The disclosed data comprised roughly sixty thousand records containing student names, dates of birth, unique identifiers and other personally identifiable information. Across all victims the attackers published approximately 382 gigabytes and twenty‑seven million records, asserting that the compromised organizations had not satisfied extortion demands.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

On July 26, 2026, the extortion group ExfilSquad first emerged and claimed to have exfiltrated data from fifteen separate organizations. By August 7, 2026, the group published data dumps for thirteen of those victims via torrent links. District of Columbia Public Schools (DCPS) was among the organizations listed in the release. The attackers stated they would not dox school children but would expose what they described as DCPS’s failure to protect information of children as young as six. Accordingly, they released a censored version of the leak and said they had shredded the original data from their own servers. The leaked material for DCPS consisted of approximately sixty thousand records.

Cyber Incident Image

The leaked data for DCPS comprises approximately sixty thousand records containing student names, dates of birth, unique student identifiers and other personally identifiable information. Fortra Intelligence and Research Experts examined public samples and confirmed the attackers’ claim of access to sensitive data was accurate. Analysis indicated the breach likely resulted from unauthorized read access to Microsoft Dynamics 365 CRM and ERP environments. The leading theory points to misconfigured Microsoft Power Pages portals that granted public read access to underlying tables. Power Pages is a software‑as‑a‑service platform for creating external‑facing websites, and the leaked data format matched Microsoft Dataverse exports. Such exports are consistent with an attacker who obtained read‑only permissions through the Anonymous Users web role assigned to a table. When that role is applied, anyone visiting the site can query the table via the Power Pages API at https://<portal>/_api/*. Microsoft documentation advises against using the Anonymous Users role on publicly exposed Power Pages sites. Fortra noted that automated scanning for exposed Power Pages instances is a common reconnaissance technique and that they identified over ten thousand potentially accessible portals during their research.

The leaked data for DCPS comprises approximately sixty thousand records containing student names, dates of birth, unique student identifiers and other personally identifiable information. The attackers’ accompanying note stated they would not dox school children but intended to expose what they described as DCPS’s failure to keep children’s information safe. They indicated they had released a censored version of the leak and had shredded the original data from their own servers. No additional information about DCPS’s detection, containment, notification or remediation actions is included in the provided source material.

Sources
Sources available to members
1 source