➤Summary
Enterprise brand protection platform teams should treat the Microsoft Power Pages and ExfilSquad story as a lesson in exposure management, not simply as another breach headline. Public reporting has connected a Microsoft Power Pages misconfiguration story with claims made by the newly emerged ExfilSquad group, but the available evidence does not establish that Microsoft itself was breached or that 27 million Microsoft records were confirmed as stolen.
Reference: https://www.cyfirma.com/resources/
That distinction matters. The underlying Power Pages security issue is real: researchers previously demonstrated that incorrectly configured access controls could expose millions of records through public-facing portals. Separately, ExfilSquad began publishing numerous unverified victim claims in July 2026, including Microsoft.
Reference: https://www.securityweek.com/low-code-high-risk-millions-of-records-exposed-via-misconfigured-microsoft-power-pages/
For security, fraud, and brand protection teams, the important question is therefore not simply whether the 27 million-record figure is accurate. It is how exposed web applications, public data, threat-actor claims, and subsequent impersonation risks should be investigated together.
What happened with Microsoft Power Pages and ExfilSquad?
Microsoft Power Pages is a low-code platform for creating externally accessible websites backed by Microsoft Dataverse. Its security model includes site visibility, authentication, web roles, table permissions, page permissions, and security controls. Microsoft explicitly warns that table permissions govern access to Dataverse data and that anonymous access can expose data to unauthenticated visitors.
Research published by AppOmni in 2024 found multiple Power Pages implementations where excessive permissions exposed sensitive information. SecurityWeek reported that researchers identified approximately seven million exposed records across several implementations, including a case involving more than 1.1 million NHS employee records. The exposures were attributed to customer configuration and access-control problems rather than a vulnerability in Microsoft Power Pages itself.
The more recent ExfilSquad story is different. CYFIRMA reported that the group emerged on July 26, 2026, and listed Microsoft among numerous alleged victims. SOCRadar similarly assessed the group as newly emerged and said its claims lacked independent confirmation, verifiable data samples, or forensic evidence.
The distinction is critical: a historical Power Pages exposure is evidence that misconfiguration can create real data exposure, but it is not proof that ExfilSquad obtained a specific number of Microsoft records through Power Pages.
Why Power Pages misconfiguration can expose sensitive records
Power Pages combines a web application with Dataverse data, which makes authorization configuration especially important. Microsoft states that table permissions control access to Dataverse information through lists, forms, Liquid, and the Web API.
The most important risk is excessive authorization for external users.
Microsoft’s documentation states that assigning the Anonymous Users web role to a table permission makes the table’s data visible to anyone who visits the site. Microsoft also provides security diagnostics specifically for anonymous access to Dataverse tables.
Earlier independent research identified several recurring contributors to exposure:
- Anonymous or broadly authenticated roles receiving excessive permissions
- Global table access granted to external users
- Web API configurations exposing more fields than necessary
- Sensitive columns lacking additional protection
- Custom code that assumes authentication or authorization controls are stronger than they actually are
- Public-facing forms, lists, or APIs whose permissions do not match the intended audience (CSA)
The security lesson is straightforward: low-code development reduces application-development effort, but it does not eliminate authorization risk.
Why the 27 million-record claim requires careful interpretation
A large number attached to a breach story can quickly become detached from its original evidence.
In this case, organizations should separate three different facts:
- Confirmed: Power Pages can expose Dataverse information when authorization is misconfigured.
- Reported: ExfilSquad listed Microsoft among its alleged victims in July 2026.
- Unverified: The connection between Microsoft’s alleged ExfilSquad incident, Power Pages, and a specific 27 million-record dataset.
SOCRadar’s assessment is particularly relevant because it found no forensic detail, independently verified samples, or reliable confirmation accompanying ExfilSquad’s initial claims. The organization also described the group’s early listings as highly questionable, with reused data or fabricated allegations possible.
That does not mean security teams should ignore the claim. It means they should investigate it as a threat-intelligence lead rather than promote it as an established breach.
How an exposed web portal can become a downstream fraud problem
A data exposure does not have to result in an immediate account takeover to create business risk.
Names, email addresses, telephone numbers, employee information, organizational relationships, or other exposed records can make later social-engineering campaigns more convincing. Attackers may use publicly available information together with breached or exposed data to construct credible phishing narratives.
This is where an enterprise brand protection platform becomes relevant.
Domain threat intelligence can help security teams look beyond the original application and identify external infrastructure that may emerge around an incident. A newly registered lookalike domain does not prove malicious activity, but a combination of domain similarity, suspicious lifecycle changes, website content, certificate activity, and phishing indicators can raise its investigative priority.
The objective is not to label every similar domain as malicious. It is to correlate signals and distinguish ordinary domain similarity from active brand abuse — how to protect brand from phishing.
How an enterprise brand protection platform can support investigation
An enterprise brand protection platform should complement, rather than replace, application security, identity controls, SIEM, EDR, email security, and incident response.
For a case involving a potentially exposed customer or employee dataset, security teams can monitor several external signals:
- Newly registered domains containing brand or product variations
- Typosquatting and homoglyph domains
- Domains moving from parked to active status
- SSL/TLS certificates issued for suspicious brand variations
- DNS changes associated with previously inactive domains
- Websites displaying unauthorized logos, login interfaces, or support content
- Domains appearing in phishing intelligence feeds
- Repeated infrastructure relationships across suspicious domains
- Domains associated with customer-facing scams or fraudulent portals
SpoofGuard provides phishing domain monitoring service and brand protection against lookalike domains, scams, and impersonation. Its technology continuously tracks certificate transparency logs, new domain registrations, DNS activity, domain age, website characteristics, and applies advanced risk scoring to detect and stop threats before they spread.
What security teams should investigate after a suspected exposure
The first priority should be validating the underlying application configuration.
1. Review Power Pages access controls
Audit site visibility, web roles, table permissions, page permissions, authentication settings, and Web API exposure. Microsoft recommends using its Security workspace to review these controls and security findings.
2. Identify anonymous access
Determine whether any Dataverse tables are accessible through the Anonymous Users role. Microsoft provides governance controls that can disable anonymous access across selected or all Power Pages sites.
3. Review exposed data
Establish exactly which tables, records, and fields were accessible and whether access was actually exercised. Separate theoretical exposure from evidence of unauthorized retrieval.
4. Correlate external indicators
Search domain intelligence, certificate transparency, DNS, phishing feeds, and web-content telemetry for activity that may indicate downstream abuse of the organization’s identity or brand.
5. Preserve evidence
Record timestamps, configuration states, relevant logs, suspicious domains, screenshots or content captures where safe, and communications from third parties. This creates an evidentiary trail for incident response and abuse reporting.
6. Escalate confirmed abuse
If a domain is independently confirmed to host phishing or fraudulent content, coordinate with the relevant registrar, hosting provider, security vendors, browser-reporting channels, and internal legal or abuse teams as appropriate.
Security Checklist
- Review Power Pages site visibility and authentication.
- Audit Anonymous Users and Authenticated Users web roles.
- Review Dataverse table permissions for least privilege.
- Check page and Web API permissions.
- Determine whether sensitive fields were unnecessarily exposed.
- Validate whether suspected data was actually accessed.
- Monitor brand-related newly registered domains.
- Investigate suspicious lookalike domains using multiple signals.
- Review certificate and DNS changes associated with suspicious domains.
- Preserve evidence before remediation or takedown activity.
- Coordinate confirmed phishing or fraud reports with appropriate providers.
- Continue monitoring after the initial incident is closed.
For organizations managing many brands, subsidiaries, products, or customer portals, continuous external visibility can reduce the gap between an internal security event and the appearance of downstream impersonation activity. SpoofGuard’s domain threat intelligence platform provides a relevant starting point for evaluating this layer of monitoring.
What MSSPs should take from the Power Pages case
MSSPs and MDR providers can treat this type of incident as a cyber threat detection problem.
A client may resolve an application misconfiguration correctly but still face secondary risks from phishing domains, fraudulent portals, or impersonation campaigns. A managed domain-monitoring workflow can therefore complement SIEM and endpoint telemetry by giving service providers visibility into external assets targeting multiple clients.
The strongest workflow is contextual rather than purely volume-driven. A newly registered domain that resembles a client brand may deserve monitoring. A domain that is active, hosts suspicious content, has relevant certificate or DNS signals, and appears in phishing intelligence deserves substantially higher priority.
That risk-based approach helps analysts avoid drowning in false positives while retaining visibility into fast-moving brand abuse.
What does this mean for organizations using Microsoft Power Pages?
The practical lesson is not that Power Pages is inherently insecure. Microsoft provides multiple controls for authentication, authorization, page access, table access, WAF configuration, and security assessment. The risk arises when those controls do not reflect the intended data-access model. Reference: https://learn.microsoft.com/en-us/power-pages/security/power-pages-security
Organizations should also avoid treating an exposure assessment as a one-time project. Public-facing applications change, permissions evolve, new tables are added, and integrations introduce new paths to data. Continuous configuration review is therefore more reliable than assuming that a previously tested portal remains secure indefinitely.
The same principle applies externally. A brand-protection program should continuously assess newly appearing domains and infrastructure rather than waiting for customers to report a fraudulent website.
Frequently Asked Questions
Was Microsoft confirmed to have exposed 27 million records through Power Pages?
No. Public reporting supports the existence of genuine Power Pages misconfiguration risks and separately documents ExfilSquad’s July 2026 claim involving Microsoft. However, available independent assessments have not established that Microsoft suffered a confirmed 27 million-record Power Pages breach. The figure and alleged attack path should therefore be treated as unverified unless stronger evidence emerges.
Reference: https://socradar.io/blog/dark-web-profile-exfilsquad
Can Power Pages expose Dataverse data to anonymous users?
Yes, if table permissions are configured to grant the Anonymous Users role access to Dataverse data. Microsoft explicitly states that anonymous table permissions can make the relevant data visible to anyone visiting the site. Organizations should therefore review anonymous access and apply least-privilege permissions based on the site’s actual business requirements.
Does a data exposure automatically create a phishing campaign?
No. Exposure and phishing are separate events. However, exposed identity or organizational information can increase the effectiveness of later social engineering. Security teams should monitor for suspicious domains, fraudulent websites, impersonation, and phishing indicators after a significant exposure while avoiding the assumption that every related domain is malicious.
How can organizations monitor domains for brand abuse?
Organizations can combine newly registered domain monitoring with lookalike detection, DNS and certificate intelligence, website-content analysis, phishing intelligence, and risk scoring. The goal is to identify domains that move from simple similarity toward observable malicious behavior. This should operate alongside email security, MFA, endpoint controls, application security, and incident response rather than replace them.
Gain visibility into domains targeting your brand
The Power Pages story illustrates why internal exposure management and external brand protection should be connected. If an organization is investigating a suspected data exposure, monitoring the external domain ecosystem can help identify potential impersonation and phishing activity that develops afterward. SpoofGuard offers domain fraud monitoring and brand-protection capabilities designed to provide that external visibility.
Unlock your free 7‑day demo now
Disclaimer: Spoofguard reports on publicly available threat-intelligence sources. Inclusion of an organization in an article does not imply confirmed compromise. All claims are attributed to external sources unless explicitly verified.
