CSIDB logo
Incident

City of Atlanta

Incident posture

Attack window
Aug 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-08-17 06:34

Linked entities

Victim
City of Atlanta
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Jul 2026
Discovered
Undetermined
Disclosed
Aug 2026
Resolved
Pending

Summary

Researchers linked the extortion group ExfilSquad to data leaks from thirteen organizations, including the City of Atlanta, after confirming that the group had exfiltrated sensitive information from Microsoft D365 CRM and ERP systems through misconfigured Power Page portals that allowed public read access. The attackers published torrents containing 382.64 gigabytes and twenty‑seven million records, with a censored release for the District of Columbia Public Schools dataset after shredding the original files, and noted that the breaches stemmed from unauthorized read access to Dataverse exports rather than a platform vulnerability.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

ExfilSquad first appeared on July 26, 2026, and claimed to have exfiltrated data from fifteen separate organizations. On August 7, 2026, the group published data dumps for thirteen of those victims via torrent files. The City of Atlanta (atlantaga.gov) was among the organizations included in the released dump. The attackers noted that the victims had not met the extortion agreements.

The total volume of the leaked data across the thirteen victims amounted to 382.64 gigabytes and twenty‑seven million records. Fortra Intelligence and Research Experts analyzed the samples and concluded that the exfiltrated data matched the structure of Microsoft Dataverse exports. This indicated that the unauthorized access likely occurred through Microsoft Dynamics 365 CRM and ERP environments. The leading theory for the initial intrusion vector is a misconfigured Microsoft Power Pages portal that granted public read access. Power Pages is a software‑as‑a‑service platform used to create external‑facing websites that can be interacted with through an API endpoint of the form https://<portal>/_api/*.

A specific misconfiguration identified by the researchers is the assignment of the Anonymous Users web role to a table permission, which allows anyone visiting the site to read the underlying table data. Microsoft’s own documentation advises against using this role on publicly exposed Power Pages sites. Fortra’s scanning efforts found more than ten thousand Power Pages instances that were accessible to the public and potentially vulnerable to similar enumeration. The City of Atlanta’s data was packaged in a file named '[atlantaga]_exfilsquad' and made available for download alongside the other victims’ archives.

Sources

Sources available to members: 1 source.

CSIDB