decrypted · 15 august 2026 · ransomware and cybercrime · supply chain · surveillance and privacy
The Power Pages default behind three UK breaches this month
Three UK institutions have spent the past fortnight separately confirming they were breached: the Department for Education, the Police National Legal Database, and Newcastle University. This week, independent researchers joined the dots on all three at once. A second threat intelligence team confirmed that the extortion crew behind them, and ten more victims worldwide, really did have the data it claimed, and traced the route in to a single overlooked setting in a single Microsoft product. That is the story worth understanding today, not the individual breach notices that trickled out over the past fortnight.
What ExfilSquad actually found
A group calling itself ExfilSquad surfaced in late July, claiming to have exfiltrated data from 15 organisations across government, education, financial services and manufacturing. On 7 August it dumped data from 13 of them via torrent, 382.64GB and roughly 27 million records, and researchers at Resecurity traced the intrusions to misconfigured Microsoft Power Pages portals: the low-code platform organisations use to expose public-facing forms and case-management systems, left with excessive read permissions for "Anonymous" or "Authenticated" visitor roles. That gave attackers direct access to the Dynamics 365 CRM and ERP data sitting behind the form, through Power Pages' own APIs. No injection, no credential theft, just a permission table nobody had locked down.
This week, a separate research team, Fortra's threat intelligence unit, independently reviewed the leaked samples and confirmed they are genuine, not padding, which raises the credibility of ExfilSquad's claims against its other named victims too.
The Department for Education says the data taken from its helpdesk portal was limited to customer service contact details: names, emails, phone numbers and job titles belonging to parents, school leaders, university staff and officials. The Police National Legal Database, used by all 43 Home Office police forces, says names, organisations and work email addresses of officers and justice staff were exposed, with no passwords or credentials involved. Neither has confirmed ExfilSquad by name, but researchers say the leaked samples match.
The design lesson
Power Pages is built for speed: tick a few boxes, publish a portal, done. The security sits in a separate permission model that is opt-in rather than opt-out, so an administrator has to actively restrict what an anonymous visitor's role can read before anything is safe to expose. Leave that step undone and every record behind the form is queryable by anyone who thinks to ask.
This is not a new failure mode. AppOmni researchers flagged the identical misconfiguration class back in November 2024, after an NHS-linked supplier exposed 1.1 million employee records the same way. Two years, and by Resecurity's count over 10,000 potentially exposed Power Pages instances later, the same default has now caught a police legal database, a government department and a university in the same fortnight. The lesson for any UK organisation running a low-code portal, whether on Power Pages or an equivalent platform, is that "public-facing form" and "public-facing database" are the same sentence unless someone has explicitly made them different. Audit the anonymous and authenticated role permissions on every externally exposed portal, and treat the platform's own configuration warnings as findings, not noise.
Also this week
A shipping vendor's flaw reached UK customers of a hardware wallet maker. Trezor disclosed that its fulfilment partner ShipMonk was breached via a SQL injection flaw in Metabase, the analytics tool Decrypted covered on 8 August. Names, addresses, phone numbers and emails of nearly 14,000 customers were exposed, including UK buyers. CISA has since added the underlying Metabase flaw, CVE-2026-72898, to its Known Exploited Vulnerabilities catalog with a CVSS score of 10.0, a reminder that a vendor's unpatched instance is every downstream customer's problem too.
Cisco's firewall VPN service can be knocked offline by a single crafted request. CVE-2026-20349, a heap inspection flaw in Cisco ASA and FTD software, lets an unauthenticated attacker crash the SSL VPN service remotely. Cisco confirmed active exploitation on 11 August; CISA added it to its exploited catalog the same week. It is only a denial-of-service, not a takeover, but for any UK organisation relying on ASA or FTD for remote access, a VPN gateway that reloads on demand is still an outage on someone else's schedule.
The Cyber Security and Resilience Bill is heading for Royal Assent with a workforce problem attached. The bill will bring managed service providers and newly designated critical suppliers into statutory scope, with mandatory 24-hour incident reporting. A report published this month warns it risks becoming a "paper tiger": 58% of government organisations already report basic cyber skills shortages, against 49% across UK business generally. Statutory deadlines are only as good as the people available to meet them.
Sources
- ExfilSquad Targets New Victims, Shares Data via Torrents
- Researchers Confirm ExfilSquad's Access to Sensitive Data
- PNLD Breach Exposes U.K. Police and Government Contact Details on Dark Web
- Trezor discloses data breach affecting nearly 14,000 customers
- U.S. CISA adds Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited Vulnerabilities catalog
- Cyber Security & Resilience Bill risks becoming 'paper tiger' without cyber skills reform, report warns
If your organisation runs a public-facing Power Pages portal, or any other low-code platform, and wants a second pair of eyes on its permissions, get in touch.
More like this
- The bill comes due for the SSO flaw that hit 138 companies 13 september 2026
- The SSO flaw that let one attacker log in as 138 companies 11 september 2026
- N-able's fourth patch in five weeks exposes the risk in remote monitoring tools 8 september 2026
Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.
Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.