CyberSecurity SEE

Researchers Confirm ExfilSquad Accessed Sensitive Data

Researchers Confirm ExfilSquad Accessed Sensitive Data

Examination of ExfilSquad’s Data Breaches Reveals Extensive Impact Across Multiple Sectors

Recent investigative efforts have uncovered substantial findings regarding the ExfilSquad data extortion group, which has been linked to breaches involving leaked data from at least 13 victims spanning an array of sectors, including government, education, financial services, and manufacturing. This group, first identified on July 26, has aggressively claimed responsibility for exfiltrating sensitive data from a total of 15 organizations.

Fortra Intelligence’s Findings

Experts from Fortra Intelligence and Research Experts (FIRE) conducted a thorough examination of data samples that the ExfilSquad has publicly released. Their analysis confirmed that the group’s assertions of possessing sensitive information were not unfounded. On August 7, the ExfilSquad took the alarming step of disseminating data dumps related to 13 of these victims via torrents, making the claim that these organizations did not adhere to previously agreed-upon terms.

The downloaded archive, labeled as “[victim]_exfilsquad,” was reported to hold an astounding 382.64 GB of data, encompassing around 27 million records from the compromised entities. Among the victims, high-profile names emerged, including the City of Atlanta, the UK Department for Education, and the UK Police National Legal Database.

One particularly concerning entry was the District of Columbia Public Schools (DCPS). The group made a pointed statement indicating that while they chose not to expose numerous school children’s information, they intended to highlight the vulnerabilities in how DCPS manages the sensitive data of its students. In a move that has drawn significant criticism, the attackers released a version of the data leak that they described as censored, claiming to have securely deleted the original records from their servers. Alarmingly, this breach involved the exposure of approximately 60,000 records that detailed student names, dates of birth, and unique student identifiers, all of which are considered personally identifiable information (PII).

Interestingly, two initial victims noted in the group’s original roster—Zenith Bank Plc and Analog Devices—were not part of the published leaks, according to FIRE’s assessment, further complicating the narrative around the extent of the group’s activities.

Mechanisms of Attack: Unauthorized Access and Misconfigured Portals

In terms of breach methodology, researchers have posited that the incidents primarily stem from unauthorized access to Microsoft D365 Customer Relationship Management (CRM) and Enterprise Resource Planning (ERP) instances. According to the FIRE team’s analysis, the prevailing theory attributes the initial avenues for data exfiltration to misconfigured Microsoft Power Pages portals, which inadvertently granted public read access to sensitive information.

Fortra researchers elucidated that Microsoft Power Pages is a Software-as-a-Service (SaaS) platform engineered for the creation, hosting, and management of modern websites tailored for external audiences. The nature of the leaked data appeared consistent with exports from Microsoft Dataverse, signifying that unauthorized access was likely secured during these reported breaches.

The attackers most likely identified their targets following systematic crawling of misconfigured Microsoft Power Portals and employing various enumeration techniques. Although the breaches resulted in 15 specific victims, the limited number suggests that vulnerabilities within D365 itself are not implicated as the source of the breaches.

FIRE noted a known issue within Microsoft Power Pages, where misassignment of the Anonymous Users web role to table permissions can result in any internet user being able to read the table’s data. Microsoft’s official documentation advises against using this role in publicly exposed environments, pointing to a gap that the ExfilSquad appears to have exploited.

Automated scanning for publicly accessible Power Pages sites has become a recognized tactic among cybercriminals. Fortra reported that its own investigations uncovered over 10,000 instances of Power Pages potentially exposed to public scrutiny, signaling a wider vulnerability landscape that could be leveraged by malicious actors.

Implications of the Breach

As organizations increasingly pivot toward digital solutions, the ramifications of such data leaks extend far beyond the immediate losses of information. The trust eroded between institutions and the public, especially in sectors handling sensitive data like education and government, can result in prolonged reputational damage. The implications for cybersecurity policy, resources, and strategies must therefore be amplified in light of these revelations.

This unfolding narrative sheds light not only on the capabilities of groups like ExfilSquad but also emphasizes the critical need for organizations to take proactive measures in securing their digital infrastructures. With hackers continuously innovating their attack methodologies, maintaining robust cybersecurity protocols has never been more paramount.

Source link

Exit mobile version