Add Fazzaco to desktop

Add Fazzaco to desktop

Access Fazzaco from desktop next time

Add now
English

FINRA warns ExfilSquad conducting data extortion campaign targeting financial services firms

Source: Fanny Maria Nikolova

The Financial Industry Regulatory Authority (FINRA) has warned financial services companies about a significant security threat that could allow unauthorized access to data stored in their Microsoft Dynamics 365 (D365) environments via a misconfigured Microsoft Power Pages portal. A threat actor group called ExfilSquad is conducting a sustained data extortion campaign against organizations across multiple industries, including financial services companies. The group exploits misconfigured permissions to gain unauthorized access to databases containing personally identifiable information (PII) of customers and employees, threatening to publicly release the stolen data unless a ransom is paid.

ExfilSquad, a threat actor group first discovered in mid-2026, is notorious for carrying out numerous high-profile data breaches in the education, government, and technology sectors. The group employs a two-pronged extortion strategy: first stealing sensitive data, then threatening to publish it on dark web forums unless a ransom is paid.

The group's primary attack method involves exploiting a misconfigured Microsoft Dynamics 365 Power Pages portal. Specifically, ExfilSquad exploited Dataverse table permissions that granted the "Anonymous Users" web role overly broad read access to sensitive entities via the Power Pages Web API. This misconfiguration allowed any unauthenticated visitor to directly query and extract sensitive data from exposed Dataverse tables, including customer and employee PIIs.

Microsoft's own documentation also advises against assigning the "Anonymous Users" web role to table permissions on publicly exposed sites. Automated scanning tools, including publicly known attack tools such as "Power Pwn," have been observed actively scanning exposed Power Pages instances. Over 10,000 potentially vulnerable public-facing Power Pages instances have been identified.

Importantly, the existing evidence does not indicate any software vulnerabilities in D365 itself being exploited, nor does it suggest typical network-level ransomware activity. The activity appears to be limited to Software-as-a-Service (SaaS) data theft and ransomware, with observed data exports consistent with the Dataverse format.

FINRA recommends that member companies using Microsoft Dynamics 365 or Microsoft Power Pages contact their IT departments, technology vendors, or managed service providers to confirm that the following measures have been implemented: Restricting Unauthorized Access: Companies should immediately audit and remediate their Power Pages and Dataverse configurations to eliminate unauthorized external access. This includes disabling anonymous access, removing the “Anonymous Users” web role from all table permissions, and restricting Web API access to only operationally necessary tables. After remediation, companies should verify that unauthenticated access attempts return an authorization error. Strengthening Authentication Controls: Companies should disable device code flow authentication at the tenant level and require re-implementation of multi-factor authentication (MFA) for all access to sensitive cloud applications (including but not limited to Microsoft Dynamics 365 and Microsoft Power Platform). Where device code flow exceptions are operationally necessary, access should be strictly limited and closely monitored. Enabling Monitoring and Detection: Companies should enable Dataverse auditing and activity logging in all Power Platform and Dynamics 365 environments and monitor for anomalous patterns in login and access logs. It is strongly recommended that companies retain all current configuration snapshots and logs before implementing remedial changes, as this information may be critical for investigative and regulatory purposes. Companies should also review their vendor risk management programs to ensure they have processes in place to address third-party security incidents, including policies, procedures, and controls related to cloud platform configuration and third-party service management.

Create Company Page