Fortra Intelligence and Research Experts (FIRE), Fortra's threat research team, shared findings in Yahoo News examining claims made by the ExfilSquad data-extortion group. The team found evidence supporting the group's claims and concluded the exposed data likely resulted from misconfigured Microsoft Power Pages portals that provided unintended access to Microsoft D365 environments. The research found no signs of ransomware or exploited vulnerabilities, pointing instead to configuration-related exposure and the risk of sensitive data being unintentionally exposed.
"Security researchers are backing claims by a newly emergent data-extortion group that it has exfiltrated sensitive data from about 15 companies, governments and other organizations."