Preface: FIRE Ransomware Project
Fortra Intelligence and Research Experts (FIRE) have developed specialist tooling to support certain customers when faced with ransomware and data extortion claims. We monitor for new disclosures, including public and dark web sources, to provide early alerting to customers and support investigations.
As part of this process, we also see activity that is not directly related to customers. When there is a significant interest, and we have new intelligence to share, we aim to share information with the security community to aid understanding of ransomware and extortion actors and campaigns.
Often ransomware actors will exaggerate claims to apply pressure as part of the extortion playbook and organizations may have valid concerns that they could be indirectly impacted.
This write-up focuses on the evidence publicly available to our researchers to validate the threat actors’ claims and current capabilities, as well as to offer recommendations for those directly and indirectly impacted in the spirit of collective defense.
Overview
ExfilSquad are an emerging data extortion group that first appeared on the 26th of July, claiming to have exfiltrated data from 15 different organizations.
The groups claims were initially met with skepticism as no supporting evidence was provided, however, on the 28th of July 2026 and the 7th of August 2026 the group released data samples to prove the sample’s authenticity and pile pressure on those impacted as part of a classic data extortion play.
Fortra Intelligence and Research Experts (FIRE) have obtained the data samples, and our analysis supports ExfilSquad’s claim that they have access to sensitive data. Analysis of the data samples strongly suggests that the exfiltrated data is limited to Microsoft D365 CRM and ERP instances.
FIRE have not found any evidence of exploited vulnerabilities, network compromise, lateral movement or encryption payloads typical of a classic ransomware attack. This is a data breach, most likely limited to unauthorized access of D365 instances.
The leading theory on the initial attack vector that enabled exfiltration is misconfigured Microsoft Power Page portals that allowed for public read access. Power Pages is a SaaS platform designed for creating, hosting, and administering modern, external-facing business websites.
The observed leaked data formats are consistent with Microsoft Dataverse exports, suggesting unauthorized read access may have been achieved, and victims found by crawling for misconfigured Microsoft Power Portals or other enumeration techniques. This was first reported by VenariX who identified a live, anonymously accessible endpoint during the investigation, and public exploit tools were later discovered utilizing this attack, with official Microsoft documentation recommending users disable anonymous read access rights.
In its initial communications with Microsoft, ExfilSquad set a deadline of August 5, 2026 for a response. We have no information indicating whether any victims have engaged with the group or what extortion deadlines, if any, ExfilSquad has since established.
(screenshot attached to data sample released by ExfilSquad on the 28th of July)
ExfilSquad have continued to add pressure with a public reminder aimed at the victims on the 5th followed by larger torrent files on the 7th.
Timeline
As of the 12th of August 2026, the timeline of key events are listed below. More detail can be found under the FIRE analysis section.
Date (2026) | Event | Key Details |
July 26 | ExfilSquad data leak site goes online and claims 15 victims as part of a data extortion ransomware attack | ExfilSquad publishes its data leak site on Tor An anonymous contact channel is provided Initial claim is met with scepticism due to a lack of full evidence provided |
July 28th | ExfilSquad disclose details on data volume and record types with a data sample as evidence | The site states that some samples are available and warns that published data will remain in the public domain Claimed data summary: 27M+ records containing significant PII and corporate data ExfilSquad provide August 5th 2026 deadline for communication Meta-data analysis suggests valid data breach Breached data appears limited to Microsoft Dynamics 365 CRM and ERP exfiltration Deadline to contact ExfilSquad: August 5, 2026 |
August 5th | Reminder issued on deadline day
| ExfilSquad claim lack of communication from victims Re-state the promised threat of data disclosure |
August 7th | Data dumps of 13 of the victims are published via torrents | ExfilSquad publishes organizations it claims did not meet an agreement Two companies, Zenith Bank Plc and Analog Devices, are silently removed from the disclosure despite earlier threats and leak meta-data being provided Warns that released data will remain public and be mirrored across the internet |
August 7th | Torrent metadata verified | Torrent metadata identifies a creation date of August 6, 2026 (UTC−6) The torrent references the archive [victim]_exfilsquad.7z A web-seed location is embedded: hxxp://209[.]99[.]188[.]199/[victim]_exfilsquad[.]7z Anonymous file sharing site u[.]pone[.]rs also used to host data leak archives
|
August 7th | Exfiltration server online
| Nginx web server observed at 209[.]99[.]188[.]199:80 The server hosts the leaked archive for download
|
August 7th | Leaked archive available
| The full archive “[victim]_exfilsquad” is made available for download (total data = 382.64 GB and 27 million records across 13 victims) Leaked data is consistent with D365 as original location of exfiltrated data The archive contains multiple folders and JSONL matching initial claims |
Diamond Model
FIRE have summarized the current known components of ExfilSquad. A more detailed analysis can be found in the next section.
FIRE Research
Our analysis is limited to openly available data on the open and dark web. Findings are inferred from this data only and we have not collaborated with the organizations referenced by ExfilSquad.
We were able to access the data samples for analysis. Our analysis suggests that this is a valid data breach, although it is unlikely to represent a full organizational level compromise as the data appears to be limited to SaaS.
Specifically, Microsoft’s D365 with the data fields and values have strong connections to Microsoft D365 CRM and ERP.
(listed fields referencing Dynamics CRM)
(a screenshot of some of the data analyzed showing D365 CRM fields)
It is expected that the user only had read access to the files, which is enough to exfiltrate the data but not enough to further a compromise.
Potential Attack Vector
No evidence has been observed of a software vulnerability within D365. If that was the case, we would expect the data breach to be on a massive scale, closer to the tens of thousands of D365 users – not 15.
No evidence has been observed of network compromise that are typical of the classic ransomware attack play. This appears to be limited to SaaS data exfiltration and data extortion.
Let’s look at the current most likely attack vector: Misconfigured and exposed Power Pages.
Microsoft’s documentation lists Power Pages as a functionality to “create external-facing websites that allow users outside their organizations to sign in with a wide variety of identities, create and view data in Dataverse, or even browse content anonymously.”
There is a known issue in Microsoft Power Pages that when the Anonymous Users web role is assigned to a table permission, the table’s data can be read by anyone visiting the site. The Power Pages can be accessed via API, specifically at https://<portal>/_api/*.
Microsoft advise against using this role in publicly exposed sites in their documentation: https://learn.microsoft.com/en-us/power-pages/security/assign-table-permissions.
The data formats observed are consistent with Dataverse exports, supporting exposed Power Pages as the likely method of access and exfiltration.
Automated scanning for exposed Power Pages sites is a known technique and has been recently abused using attack tools such as Power Pwn.
We were able to identify over 10,000 potential Power Pages instances accessible to the public.
Data Types Exposed
Upon reaching the disclosure deadline, ExfilSquad released the full data leaks via their Tor Onion blog site. The 13 final victims operate in a variety of verticals and variance in data types is therefore expected.
(Top 5 affected sectors)
Multiple Torrents were released with torrent magnet links and the following files, including notes and summaries provided by ExfilSquad.
Initial analysis of the file dumps corroborates ExfilSquads claims presented in the data summary. The below is copied directly from ExfilSquad’s leak page:
Allstate - allstate_exfilsquad.7z.torrent
SIZE : 15.1 GB UNCOMPRESSED
DATA SUMMARY: 657K~ records containing: significant PII, recruitment and licensing information, onboarding data, and internal employee account information.
City of Atlanta (atlantaga.gov) - atlanta311_exfilsquad.7z.torrent
SIZE : 36.3 GB UNCOMPRESSED
DATA SUMMARY: 3M~ records containing: significant PII, citizen service requests, addresses, municipal case history, and internal case management data.
Bonava - bonava_exfilsquad.7z.
torrent SIZE : 13.2 GB UNCOMPRESSED
DATA SUMMARY: 842K~ records containing: significant PII, property ownership/interests, warranty and repair cases, contractor information, marketing preferences, and customer service history.
District of Columbia Public Schools (dcps.dc.gov) - dcps_exfilsquad.7z.torrent
SIZE : 200 MB UNCOMPRESSED
ExfilSquad note:“We are not going to dox a bunch of school children, but we are going to expose how incompetent DCPS is at keeping children as young as six's information safe. Thus, we are releasing a censored version of the leak and have shredded the original entirely from our servers." DATA SUMMERY: 60K~ records containing: students names, dates of birth, home addresses, phone numbers, unique student identifiers, school assignments, grade levels, registration status information.
UK Department for Education (education.gov.uk) - Dfe.7z.torrent
SIZE : 440 MB UNCOMPRESSED
DATA SUMMARY: Help Portal (~600K records) – Parent and staff contact records containing full names, email addresses, phone numbers, and job titles. Turing Portal (~7K records) – Contact records containing full names, email addresses, phone numbers, and job titles.
Frontier Airlines - frontier_airlines_exfilsquad.7z.torrent
SIZE : 43 GB UNCOMPRESSED
DATA SUMMARY: 2.4M~ records containing: significant PII, customer support cases, flight and travel information, complaint records, baggage details, and customer support email communications.
City of Houston (houstontx.gov) - houston311_exfilsquad.7z.torrent
SIZE : 71 GB UNCOMPRESSED
DATA SUMMARY: 6M~ records containing: significant PII, resident contact details, service requests, complaint descriptions, addresses, location data, case/ticket metadata, department routing, service status, resolution information, and extensive CRM metadata.
Microsoft - microsoft_exfilsquad.7z.torrent
SIZE : 130 GB UNCOMPRESSED
DATA SUMMARY: 8M~ records containing: significant PII, employee and customer contact information, authentication data, password hashes, portal identities, corporate account information, business leads, facilities management records, internal service tickets, and access permissions.
Newcastle University (ncl.ac.uk) - newcastle_exfilsquad.7z.torrent
SIZE : 240 MB UNCOMPRESSED
DATA SUMMARY: 440K~ records containing: applicant and student contact information, significant PII, and admissions data.
UK Police National Legal Database - Pnld.7z.torrent
SIZE : 1.9 GB UNCOMPRESSED
DATA SUMMARY: 135k law enforcement contact records with first/last name, email, police force area, etc.
TaylorMade & Sun Day Red golf - taylormade_exfilsquad.7z.torrent
SIZE : 22 GB UNCOMPRESSED
DATA SUMMARY: 2M~ records containing: significant PII, customer support history, orders, shipping information, business account data, financial/account information, internal notes, attachments, and AI support chat transcripts.
Viavi Solutions - viavisolutions_exfilsquad2.7z.torrent
SIZE : 9.3 GB UNCOMPRESSED
DATA SUMMARY: 430K~ records containing: customer and partner contact information, significant PII, and enterprise account identifiers.
Wesco International - wesco_exfilsquad.7z.torrent
SIZE : 40 GB UNCOMPRESSED
DATA SUMMARY: 2.6M~ records containing: customer and employee PII, account and contact data, CRM user profiles, credit and business identifiers, authentication metadata, and access information.
Zenith Bank Plc and Analog Devices were not present, despite being included in the original 15 victim list.
Meta-data Analysis and Attribution Indicators
FIRE analysis of the files identified URLs showing where a true copy of the file is held. The IP address uncovered is 209[.]99[.]188[.]199. Fortra Threat Brain, our platform for aggregated threat intelligence, flagged this IP as known malicious.
IPinfo placed the entire 209.99.188.0/24 in Switzerland, while the ASN itself is registered in Saint Kitts & Nevis (KN).
It is more likely that the infrastructure is located in Switzerland than Saint Kitts & Nevis. This is because the Swiss geolocation isn't isolated to 209.99.188.199; the entire /24 is being geolocated to Switzerland, and another independent IP-intelligence source maps the range to Zürich.
We cannot be certain that the servers reside in Zürich. IP geolocation is an inference, and the IP could be routed through a Swiss datacenter while the actual machine is elsewhere. The ASN's registration and the apparent infrastructure location can legitimately differ.
The block is extremely new: the database reports that AS402253 was allocated on March 4, 2026.
That makes the conflicting geolocation particularly unsurprising. Newly allocated/transferred IP space often takes time to propagate through the many commercial geolocation and reputation databases.
This IP address was marked as a botnet host, First Seen 2026-06-15 08:43:10 UTC, hosting a malicious ScreenConnect backdoor executable and corroborated from multiple sources.
Malicious file URL https://209[.]99[.]188[.]199/Bin/ScreenConnect[.]ClientSetup.exe
We also identified multiple URLs hosting the data dumps via extracting the torrents WebSeed values:
WebSeed: http://209.99.188[.]199/frontier_airlines_exfilsquad.7z
WebSeed: http://209.99.188[.]199/houston311_exfilsquad.7z
WebSeed: http://209.99.188[.]199/microsoft_exfilsquad.7z
WebSeed: http://209.99.188[.]199/taylormade_exfilsquad.7z
WebSeed: https://u[.]pone[.]rs/blhuvazu.7z
WebSeed: https://u[.]pone[.]rs/lmvtykhp.7z
WebSeed: https://u[.]pone[.]rs/lujsqaaz.7z
WebSeed: https://u[.]pone[.]rs/qzhwfozd.7z
WebSeed: https://u[.]pone[.]rs/rdednkgw.7z
WebSeed: https://u[.]pone[.]rs/sdjpehre.7z
WebSeed: https://u[.]pone[.]rs/udvwhagk.7z
WebSeed: https://u[.]pone[.]rs/wjuyjizy.7z
WebSeed: https://u[.]pone[.]rs/wozlrrpa.7z
The second WebSeed location points to a URL hosted at ‘u.pone.rs’
‘u.pone.rs’ is an anonymous file-hosting subdomain of ‘Pone.rs’, commonly used for sharing media within online pony fandom communities.
References to Pone.rs can be found in 4chan's /mlp/ community, where users have used the service alongside other anonymous file hosts. This association should not, by itself, be interpreted as evidence that the hosting service is operated by the ransomware group.
Other instances of ‘Pone’/related naming conventions in the hacker community include Pony Stealer (also known as Pony Loader) - a Windows-based information-stealing Trojan active since 2011.
Recommendations
Anyone who is concerned that their Power Pages portals are exposed and could be targeted for data exfiltration are strongly encouraged to run the below linked script to check for exposure.
Modules: Power Pages
Run the following command to test a specific url for anonymous access to Dataverse tables via power pages, either via the apis or odata feeds: powerpages -url https://<your_domain>.powerappsportals.com.
If you are exposed then the following recommendations apply:
Immediate actions - first 24 hours
Temporarily block anonymous access to business data across all Power Pages and legacy portals.
Direct the Power Platform administrator to block anonymous Dataverse access tenant wide.
Manage this event as a suspected security incident and engage with cybersecurity, legal, privacy, communications, insurance and business leadership teams.
Preserve portal settings, access permissions, audit records, security logs, attacker communications and published data samples before or during containment.
Identify affected portals, exposed data categories, estimated record counts, attachments, exposure dates and affected customers or employees, reporting confirmed access and potential exposure as separate events.
Rotate credentials, API keys, access codes or financial instructions found in exposed CRM records. Prepare targeted notifications and support for affected individuals where required. Avoid password resets unless there is evidence that account credentials were exposed or compromised.
Short-term actions - 2 to 14 days
Record each portal’s owner, business purpose, connected Dataverse environment, public status, authentication method and data accessed. The Power Platform admin center can identify sites that allow anonymous access to Dataverse tables.
Enforce the implementation of a zero-trust architecture.
For Power Pages:
Verify explicitly: Authenticate users before allowing them to view business data. Confirm identity, role and authorization for each access request.
Use least privilege: Allow access only to the necessary records, fields and actions. Separate public submission capabilities from authenticated record access.
Assume breach: Maintain logs, detect unusual downloads, minimize the amount of sensitive information available through portals and regularly test controls from outside the organization.
Test each site as an unauthenticated user to confirm that no sensitive records can be accessed or downloaded.
Review Power Automate, SharePoint, Power BI, payment services, custom connectors, service accounts, exports and other systems connected to the affected Dataverse environment in order to discard possible lateral movements.
Document the data involved, affected jurisdictions, risk to individuals, legal conclusions and notification deadlines for each decision.
Final Thoughts
A ransomware incident can no longer be viewed simply as an availability problem. Data exfiltration can create a much longer-lasting risk, particularly when credentials, personal information, vulnerable individuals’ data or internal business information are involved.
Organizations should focus not only on restoring systems, but also on determining what was accessed, what was stolen, who is affected, and how the stolen information could be abused.