CTIPilot

Microsoft Power Apps

product · product:microsoft-power-apps

Coverage timeline
1
first 2026-07-31 → last 2026-07-31
Peak priority
high
1 high
Sources cited
12
11 hosts
Sections touched
1
active-threats
Co-occurring entities
6
see Co-occurring entities below
ATT&CK techniques
4
pinned v19.2 · see below

ATT&CK techniques

4 techniques observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-07-31/exfilsquad-uk-department-for-education-pnld-breach · ATT&CK page ↗

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-07-31/exfilsquad-uk-department-for-education-pnld-breach · ATT&CK page ↗

Persistence TA0003

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-07-31/exfilsquad-uk-department-for-education-pnld-breach · ATT&CK page ↗

Privilege Escalation TA0004

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-07-31/exfilsquad-uk-department-for-education-pnld-breach · ATT&CK page ↗

Stealth TA0005

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-07-31/exfilsquad-uk-department-for-education-pnld-breach · ATT&CK page ↗

Collection TA0009

T1213Data from Information Repositories×1

Adversaries may leverage information repositories to mine valuable information. Information repositories are tools that allow for storage of information, typically to facilitate collaboration or information sharing between users, and can store a wide variety of data that may aid adversaries in further objectives, such as Credential Access, Lateral Movement, or Defense Evasion, or direct access to the target information. Adversaries may also abuse external sharing features to share sensitive documents with recipients outside of the organization (i.e., Transfer Data to Cloud Account).

Evidence: 2026-07-31/exfilsquad-uk-department-for-education-pnld-breach · ATT&CK page ↗

T1530Data from Cloud Storage×1

Adversaries may access data from cloud storage.

Evidence: 2026-07-31/exfilsquad-uk-department-for-education-pnld-breach · ATT&CK page ↗

Story timeline

  1. 2026-07-31UK Department for Education confirms a breach of two public-facing portals and a police legal database, claimed by ExfilSquad, a five-day-old extortion brand whose other 14 claims look fabricated
    active-threatsOne confirmed government breach inside a leak-site victim list that a threat-intel vendor assesses is more likely invented than real

Where this entity is cited

  • active-threats1

Source distribution

  • bleepingcomputer.com2 (17%)
  • cyberinsider.com1 (8%)
  • cybersecuritydive.com1 (8%)
  • infosecurity-magazine.com1 (8%)
  • pnld.co.uk1 (8%)
  • sec.gov1 (8%)
  • security-hub.ncsc.admin.ch1 (8%)
  • socradar.io1 (8%)
  • other3 (25%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

All cited sources (12)

Entries about Microsoft Power Apps (1)

2026-07-31 · view entry permalink →

HIGHexploitedupdatedNATOB2

UK Department for Education confirms a breach of two public-facing portals and a police legal database, claimed by ExfilSquad, a five-day-old extortion brand whose other 14 claims look fabricated

The UK Department for Education has confirmed a breach of two public-facing portals, the DfE Help Desk Self-Service Portal and the Turing Scheme Portal, with the compromised material described as customer-service contact details, names, email addresses and phone numbers belonging to parents, officials, school leaders and university staff (The Record, 2026-07-30). Separately affected was the Police National Legal Database, where 135,000 records identify police officers by name, force and work email address; The Record notes the database holds no protected information from investigations or witnesses, and that the Home Office, which owns it, declined to comment. The NCSC has confirmed it is supporting law enforcement colleagues on the response. The extortionists are demanding a ransom; The Record notes that as a matter of policy the British government does not make ransom payments, and that the government has moved forward with plans, not yet law, to make such payments illegal for public-sector entities.

Two details in DfE's own response are worth carrying rather than the headline number. It explicitly corrects the criminals' framing, clarifying that the claimed figure of more than 600,000 pieces of data refers to lines of data rather than the count of individuals affected, a victim disputing the arithmetic behind an extortion claim rather than repeating it. And it assesses the risk to individuals as not high, which is consistent with contact-detail exposure rather than anything more sensitive.

The claimant is where this gets interesting. ExfilSquad's Tor leak site first appeared on 2026-07-26 and immediately listed 15 organisations across government, education, finance and technology. SOCRadar's profile of the group is unusually direct about what that list is worth: it assesses that the listings may involve reused data or fabricated allegations, with fabrication currently appearing more likely (SOCRadar, 2026-07-28). No forensic evidence, data samples, victim confirmations or technical detail about initial access are publicly available for the group, and SOCRadar found no aliases, predecessor operations or rebranding history; this is a brand with no track record at all. It also documents the group posting on social media tagging a major vendor's security-intelligence account with a screenshot resembling an internal directory record, authenticity unconfirmed, which reads as publicity-seeking rather than proof.

So the same list contains one independently confirmed national-government breach and fourteen claims a credible vendor thinks are probably invented. One of the listed companies, semiconductor manufacturer Analog Devices, was added and then quietly removed; the outlet that reported the removal says the reason is unknown and notes that delisting is common when ransom negotiations begin (BleepingComputer, 2026-07-30). Analog Devices separately filed a regulatory disclosure stating it identified unauthorized access to certain systems on 23 June 2026, that its investigation found certain files were exfiltrated, and that it does not believe the incident is reasonably likely to materially impact its business, filed under the non-material "Other Events" item despite the acknowledged exfiltration, which is itself a useful materiality-threshold data point for anyone calibrating their own disclosure playbook (Analog Devices, 2026-07-29). The company has not attributed that intrusion to ExfilSquad or confirmed the group's claims are related, and the record count circulating alongside it is the group's own allegation rather than a company figure (CyberInsider, 2026-07-30). Those are two threads, and the available reporting does not join them.

135,000 pieces of data potentially identifying the names, forces and work email addresses of police officers

The Record (Recorded Future News) 2026-07-30

the listings may involve reused data or fabricated allegations, with fabrication currently appearing more likely

SOCRadar 2026-07-28

Information including the names, organisations and work email addresses of police officers, staff and other criminal justice professionals, government partners and customers has been compromised and published on the dark web.

There is no evidence to suggest that passwords or other security credentials have been compromised.

Police National Legal Database

VenariX has not identified evidence of ransomware deployment, malware use, lateral movement, or exploitation of a software vulnerability.

VenariX 2026-07-29

That is a user-base figure, not a breach-victim count.

At this stage, the Power Pages link remains a hypothesis to test rather than an explanation of the PNLD breach.

The Hacker News 2026-08-03

Unauthenticated attackers can access and exfiltrate sensitive personal, financial, and organizational data from public-facing portals via exposed Dataverse tables.

Current exploitation status: Actively Exploited

NCSC Switzerland / GovCERT.ch 2026-08-04

We have worked with our cloud CRM vendor on the matter, and we do not believe that there is a risk to sensitive data.

Wesco International, via BleepingComputer

found no evidence of ransomware or other malicious software on its IT systems

BleepingComputer 2026-07-30

The leading theory on the initial attack vector that enabled exfiltration is misconfigured Microsoft Power Page portals that allowed for public read access

Fortra FIRE, quoted by Infosecurity Magazine

it was able to identify over 10,000 potential Power Pages instances accessible to the public

Infosecurity Magazine, reporting Fortra's research

the total data was reported to be 382.64 GB and 27 million records across the 13 victims

Infosecurity Magazine 2026-08-14
Updaterun 2026-08-04T0411Z-intelactionsaffected_productsevidenceprioritysectorssourcestagsbody

The earlier entry recorded the Police National Legal Database as "affected" with a 135,000-record figure taken from third-party reporting while the Home Office declined to comment. Three things have changed, and one of them is a correction to the numbers.

The victim has now published its own statement. PNLD, operated by West Yorkshire Police, confirms that "Information including the names, organisations and work email addresses of police officers, staff and other criminal justice professionals, government partners and customers has been compromised and published on the dark web", that "There is no evidence to suggest that passwords or other security credentials have been compromised", that the incident was identified on Sunday 2026-07-26, that all affected organisations were contacted, and that it is working with the National Crime Agency and specialist cyber-security firms with the Information Commissioner's Office notified (PNLD, 2026-08-03). The statement adds a second affected service the earlier entry did not carry: Ask the Police, the public enquiry site PNLD hosts, from which names and email addresses of citizens who had previously submitted questions were also published. PNLD stresses what it is not, not the Police National Computer, not the Police National Database, not a crime-recording system, and holding no confidential material on victims, witnesses or offenders (The Hacker News, 2026-08-03).

On scope, the correction runs the other way from the usual pattern. PNLD's notice describes the exposed fields and gives no victim total at all, and as of 2026-08-03 it had not disclosed how many people were affected, when the intrusion began, how long access lasted or how much data was taken. The 108,429 figure circulating alongside this incident comes from PNLD's own 2025-26 annual summary of police registrations across all 43 Home Office forces, and the reporting is explicit that "That is a user-base figure, not a breach-victim count." Treat both that number and the earlier 135,000 as unconfirmed for scope purposes.

The access path is the transferable part, and it is a campaign-level finding rather than a PNLD root cause. VenariX reviewed data samples associated with 11 of the 15 organisations ExfilSquad listed and found the structure and field formatting consistent with Microsoft Dataverse exports across all 11, @odata.etag, @OData.Community.Display.V1.FormattedValue and @Microsoft.Dynamics.CRM.lookuplogicalname artefacts across contacts, accounts, incidents, emails, annotations, leads, system users and business units. Its assessment is that the data came out of public Microsoft Power Pages portals configured to let anonymous visitors read Dataverse records, through the portal Web API /_api/<EntitySetName> route or a legacy /_odata feed. Crucially there is no exploit in the chain: "VenariX has not identified evidence of ransomware deployment, malware use, lateral movement, or exploitation of a software vulnerability." VenariX reproduced the condition once, against the City of Houston's public Power Apps portal serving Houston 311, which returned incident records without authentication in a form consistent with what ExfilSquad published (VenariX, 2026-07-29). VenariX is equally explicit about its own limit: the evidence does not confirm that every listed organisation was reached the same way, or through the same configuration issue. PNLD is not mentioned anywhere in that research at all, and the reporting that connects the two is explicit about the gap, as of 2026-08-03 neither PNLD's notice nor VenariX's report identified a PNLD-specific endpoint, permission setting, API route or supporting log, so "At this stage, the Power Pages link remains a hypothesis to test rather than an explanation of the PNLD breach" (The Hacker News, 2026-08-03). What is corroborated is only the platform: PNLD's 2023-24 annual summary states the database uses Microsoft Power Platform, and the breach-notice page references assets on Microsoft's content.powerapps.com domain.

This also revises the earlier entry's editorial line. That entry carried an assessment that ExfilSquad's 15-victim list was more likely fabricated than genuine. The correct current read is narrower and more useful: the individual claim still deserves base-rate scepticism, but the method is now evidenced, 11 structurally consistent Dataverse sample sets, one reproduced live, one listed company (Frontier Airlines) having already confirmed unauthorised access to a data storage account on 2026-07-09 without attributing it, so the method should be swept for locally regardless of whether any given listing is real.

Updaterun 2026-08-05T0412Z-intelactionsaffected_productsevidenceregionssourcestagstechniquesbody

Switzerland's NCSC published a TLP:CLEAR advisory on 2026-08-04 stating that unauthenticated attackers can access and exfiltrate sensitive personal, financial and organizational data from public-facing portals via exposed Dataverse tables, and recording the current exploitation status as actively exploited (NCSC Switzerland / GovCERT.ch, 2026-08-04). The exposure arises where the "Anonymous Users" web role has been granted excessive read permissions on Dataverse tables, which makes the underlying records publicly readable to anyone who asks; NCSC-CH names Microsoft Power Pages and Microsoft Power Apps Portals as the affected products.

The campaign is not new here; the access-path analysis and the confirmed UK victim disclosures were covered on 2026-07-31 and 2026-08-04. What changed is the jurisdiction and the standing: until now this was foreign-incident reporting about portals belonging to other governments. The Swiss national authority issuing its own advisory to its own constituency converts it into a configuration-review duty for Swiss federal, cantonal and communal Power Pages estates, which are a common vehicle for exactly this kind of citizen-facing service.

NCSC-CH's recommended actions are to disable anonymous access, review table permissions, disable unnecessary Web API and OData feeds, and validate endpoint restrictions from an unauthenticated browser session (NCSC Switzerland / GovCERT.ch, 2026-08-04).

Triage: anonymous read access is a legitimate and intended configuration for genuinely public content, so its presence is not by itself a finding. The discriminator is which tables answer: a portal publishing a public register is doing its job, while the same anonymous role returning contact records, case data or internal identifiers is the misconfiguration the advisory describes.

Updaterun 2026-08-12T0411Z-intelaffected_productsevidenceregionssectorssourcestechniquesbody

The ExfilSquad campaign (whose leak-site list a threat-intelligence vendor assessed was more likely fabricated than real, but which contained a genuine UK government breach) has produced its first victim to answer on the record in partial terms. Wesco International, a US industrial and electrical distributor, confirmed to BleepingComputer that it is investigating a claim of CRM data exfiltration by a third party, after ExfilSquad claimed 2.6 million records taken from its cloud CRM environment (BleepingComputer, 2026-08-11). The company's spokesperson states "We have worked with our cloud CRM vendor on the matter, and we do not believe that there is a risk to sensitive data", and the company "found no evidence of ransomware or other malicious software on its IT systems", with no business disruption reported.

Two things happened in sequence and both matter. After the deadline for Wesco to enter ransom negotiations expired, ExfilSquad published the data it says it exfiltrated (BleepingComputer, 2026-08-11), so this is a completed publication event, not a pending threat. And Wesco's posture is a third distinct response pattern from this campaign's victims: the UK Department for Education and the Police National Legal Database both issued full confirmations with corrected scope, other named victims have said nothing at all, and Wesco concedes the incident while contesting its severity. A triage queue that ingests leak-site feeds now has three calibration points from one actor: confirmed-and-detailed, confirmed-but-disputed, and unanswered.

The technical half needs its hedge stated plainly, because the reporting is careful and it would be easy to over-read. What BleepingComputer says is two separate things: that research from Resecurity and VenariX indicates the group "has targeted in the past improperly configured Microsoft Power Pages data tables", and that while Wesco has not shared how it was breached, "publicly available information indicates that Wesco may be using Microsoft Dynamics 365" (BleepingComputer, 2026-08-11). No source joins those two into a finding that this breach used a Dynamics 365 surface, and no source states the group's targeting has widened. The honest read is that the documented mechanism remains anonymously readable Power Pages data tables (no exploit, no malware, just data a portal was configured to serve to anyone) and that this victim's root cause is undisclosed.

Triage: exfiltration through an over-permissioned anonymous web role produces no exploit signature and no malware, so endpoint and network telemetry will be silent by construction, which is consistent with Wesco finding no ransomware or malicious software on its systems while an incident had nonetheless occurred. What it does produce is bulk read volume against Dataverse tables attributed to the anonymous or portal service identity rather than to a named user; the discriminator against a legitimately public portal is the breadth of tables touched and the sequential, high-rate access pattern, not the identity itself, which is supposed to be reading something.

Updaterun 2026-08-16T0411Z-intelevidenceregionssectorssourcestagsbody

The open question across this pipeline's ExfilSquad coverage has been whether the group's claims were real and how it obtained the data. A second intelligence team has now answered the first and narrowed the second. Fortra's intelligence and research team reviewed the data samples the group made public and concluded that its claim to hold sensitive data is correct, tying at least 13 victims to leaked data across government, education, financial services and manufacturing (Infosecurity Magazine, 2026-08-14). The archive was published by torrent on 2026-08-07 after the group said those organisations did not meet its terms, totalling 382.64 GB and 27 million records across the 13 (Infosecurity Magazine, 2026-08-14). Two organisations from the original list of 15 (a bank and a semiconductor manufacturer) were absent from the dump.

The victim set is broader than the UK public-sector cases this pipeline has carried. Alongside the UK Department for Education and the Police National Legal Database, it includes the City of Atlanta and District of Columbia Public Schools, where 60,000 records containing student names, dates of birth and unique student identifiers were leaked in a version the group said it had censored (Infosecurity Magazine, 2026-08-14).

On the access path, Fortra's finding is a narrowing rather than a confirmation, and the distinction is worth preserving: its leading theory is misconfigured Power Pages portals allowing public read access, with the leaked data structures consistent with Dataverse exports and no evidence found of a vulnerability being exploited or ransomware deployed (Infosecurity Magazine, 2026-08-14; Cybersecurity Dive, 2026-08-14). Fortra reasons that because the campaign reached roughly 15 victims rather than tens of thousands, a platform vulnerability is unlikely to be the source, a configuration error reproduces per tenant, a product flaw would not (Infosecurity Magazine, 2026-08-14).

What is new against this pipeline's 2026-08-04 and 2026-08-05 entries is the mechanism stated at field precision and the exposure counted. The known Power Pages issue Fortra points to is that when the Anonymous Users web role is assigned to a table permission, that table's data can be read by anyone visiting the site, reachable through the portal's own API path, and Microsoft's documentation advises against using that role on publicly exposed sites (Infosecurity Magazine, 2026-08-14). Fortra reports it was able to identify over 10,000 potential Power Pages instances accessible to the public, and notes that automated scanning for exposed Power Pages sites is a known technique; victims were likely found by crawling for misconfigured portals rather than targeted (Infosecurity Magazine, 2026-08-14).

Triage: for an estate running these portals, alert-side evidence of this activity is close to absent by construction; an anonymous read through the portal API is indistinguishable in authentication telemetry from a legitimate public page view, and neither a failed-logon spike nor a new-account artifact appears. The available signals are volumetric rather than behavioural: sustained sequential requests to the portal's API path from a single source, request patterns that walk table or record identifiers in order, and response sizes far larger than the site's ordinary page traffic. Treat an absence of alerts here as uninformative, and settle the question from the permission configuration instead.

incident31 Jul 04:09Zmulti-sourceOpen finding ↗