Menu
Browse

Cyber Incident Victim: Department for Education

Date

Aug 2026

Location

United Kingdom

Status

Unknown

Updated

2026-08-17 06:28

Timeline
Occurred
Jul 2026
Discovered
Undetermined
Disclosed
Aug 2026
Resolved
Pending
Summary

Researchers confirmed that the extortion group ExfilSquad obtained and released sensitive data from 13 organizations, including the UK Department for Education, after exploiting misconfigured Microsoft Power Page portals that granted public read access to underlying Dataverse tables. The leaked archive totaled 382.64 gigabytes and 27 million records, with a separate release exposing 60,000 student records from District of Columbia Public Schools after the group claimed it would not dox children but highlighted the district’s security shortcomings.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 2 motives 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

On July 26, 2026, the extortion group ExfilSquad emerged and claimed to have exfiltrated data from fifteen separate organizations. On August 7, 2026, the group published data dumps for thirteen of those victims via torrent sites, asserting that the affected organizations had not met extortion demands. Among the victims named in the release were the City of Atlanta, the UK Department for Education (education.gov.uk), the UK Police National Legal Database, and the District of Columbia Public Schools. The archive for each victim was labeled '[victim]_exfilsquad' and made available for download. The combined size of the published data was reported as 382.64 gigabytes containing approximately twenty‑seven million records across the thirteen victims.

Cyber Incident Image

Fortra Intelligence and Research Experts examined samples of the leaked data and confirmed that the group's claims of access were accurate. The researchers noted that the leaked file structures resembled Microsoft Dataverse exports, indicating unauthorized read access to Microsoft Dynamics 365 CRM and ERP environments. They identified the most probable initial attack vector as misconfigured Microsoft Power Pages portals that granted public read access, specifically when the Anonymous Users web role was assigned to table permissions. Power Pages, a SaaS platform for external‑facing websites, can be queried through the API endpoint https://<portal>/_api/*. Microsoft’s guidance advises against using this role on publicly exposed sites. Fortra also observed that the attackers likely located victims by scanning for exposed Power Pages or using similar enumeration techniques, and that the limited scale of the breach—affecting only fifteen organizations—makes a widespread Dynamics 365 vulnerability an unlikely cause.

Sources
Sources available to members
1 source