Cyber Incident Victim: Department for Education
Timeline
Summary
Researchers confirmed that the extortion group ExfilSquad obtained and released sensitive data from 13 organizations, including the UK Department for Education, after exploiting misconfigured Microsoft Power Page portals that granted public read access to underlying Dataverse tables. The leaked archive totaled 382.64 gigabytes and 27 million records, with a separate release exposing 60,000 student records from District of Columbia Public Schools after the group claimed it would not dox children but highlighted the district’s security shortcomings.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 2 motives | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
On July 26, 2026, the extortion group ExfilSquad emerged and claimed to have exfiltrated data from fifteen separate organizations. On August 7, 2026, the group published data dumps for thirteen of those victims via torrent sites, asserting that the affected organizations had not met extortion demands. Among the victims named in the release were the City of Atlanta, the UK Department for Education (education.gov.uk), the UK Police National Legal Database, and the District of Columbia Public Schools. The archive for each victim was labeled '[victim]_exfilsquad' and made available for download. The combined size of the published data was reported as 382.64 gigabytes containing approximately twenty‑seven million records across the thirteen victims.

Fortra Intelligence and Research Experts examined samples of the leaked data and confirmed that the group's claims of access were accurate. The researchers noted that the leaked file structures resembled Microsoft Dataverse exports, indicating unauthorized read access to Microsoft Dynamics 365 CRM and ERP environments. They identified the most probable initial attack vector as misconfigured Microsoft Power Pages portals that granted public read access, specifically when the Anonymous Users web role was assigned to table permissions. Power Pages, a SaaS platform for external‑facing websites, can be queried through the API endpoint https://<portal>/_api/*. Microsoft’s guidance advises against using this role on publicly exposed sites. Fortra also observed that the attackers likely located victims by scanning for exposed Power Pages or using similar enumeration techniques, and that the limited scale of the breach—affecting only fifteen organizations—makes a widespread Dynamics 365 vulnerability an unlikely cause.
