RESEARCHERS have confirmed that the ExfilSquad data extortion group has exfiltrated sensitive data from at least 13 organizations across various sectors, including government and education, with experts validating the group's claims about their access. Following the initial emergence of the group in July 2026, they published 382.64 GB of data, totaling around 27 million records from the leaked organizations.
The data breaches are believed to stem from unauthorized access via misconfigured Microsoft D365 CRM and ERP instances, specifically through Power Pages. This incident highlights the vulnerability associated with improper configurations in Microsoft's services.