Cyber Incident Victim: City of Atlanta
Timeline
Summary
Researchers linked the extortion group ExfilSquad to data leaks from thirteen organizations, including the City of Atlanta, after confirming that the group had exfiltrated sensitive information from Microsoft D365 CRM and ERP systems through misconfigured Power Page portals that allowed public read access. The attackers published torrents containing 382.64 gigabytes and twenty‑seven million records, with a censored release for the District of Columbia Public Schools dataset after shredding the original files, and noted that the breaches stemmed from unauthorized read access to Dataverse exports rather than a platform vulnerability.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
ExfilSquad first appeared on July 26, 2026, and claimed to have exfiltrated data from fifteen separate organizations. On August 7, 2026, the group published data dumps for thirteen of those victims via torrent files. The City of Atlanta (atlantaga.gov) was among the organizations included in the released dump. The attackers noted that the victims had not met the extortion agreements.

The total volume of the leaked data across the thirteen victims amounted to 382.64 gigabytes and twenty‑seven million records. Fortra Intelligence and Research Experts analyzed the samples and concluded that the exfiltrated data matched the structure of Microsoft Dataverse exports. This indicated that the unauthorized access likely occurred through Microsoft Dynamics 365 CRM and ERP environments. The leading theory for the initial intrusion vector is a misconfigured Microsoft Power Pages portal that granted public read access. Power Pages is a software‑as‑a‑service platform used to create external‑facing websites that can be interacted with through an API endpoint of the form https://<portal>/_api/*.
A specific misconfiguration identified by the researchers is the assignment of the Anonymous Users web role to a table permission, which allows anyone visiting the site to read the underlying table data. Microsoft’s own documentation advises against using this role on publicly exposed Power Pages sites. Fortra’s scanning efforts found more than ten thousand Power Pages instances that were accessible to the public and potentially vulnerable to similar enumeration. The City of Atlanta’s data was packaged in a file named '[atlantaga]_exfilsquad' and made available for download alongside the other victims’ archives.
