Data breach
Microsoft
- Records
- 4,036,317
- Breach date
- 26 July 2026Estimated
- Added
- 9 August 2026
What was exposed
4 types of data · 1 more reported
- Email addresses4,036,317
- Names2,447,926
- Phone numbers371,175
- Street addresses4,889
- PasswordsReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
A newly emerged data extortion group calling itself ExfilSquad listed Microsoft on its dark web leak site on July 26, 2026, claiming it had stolen roughly 130 GB of data from the company. According to our investigation team, the listing tied to this breach contains about 4 million records. After initial skepticism from researchers, the group released data samples, and an August report from security firm Fortra corroborated the claim. Researchers believe the data was drawn from Microsoft Dynamics 365 customer relationship and resource planning instances, likely exposed through misconfigured Power Pages portals that allowed public read access. Fortra found no evidence of an exploited vulnerability, ransomware, or broader network compromise.
Breach Timeline
July 26, 2026: ExfilSquad published Microsoft on its dark web leak site, claiming to hold about 130 GB of uncompressed data with nearly 8 million records, and set a negotiation deadline of August 5, 2026, according to CYFIRMA.
July 28, 2026: The group released data samples and record type details as evidence, per Fortra.
August 5, 2026: ExfilSquad issued a public reminder that its deadline had passed without contact from victims, per Fortra.
August 7, 2026: The group published data dumps of 13 victims via torrent, warning that the released data would remain public, per Fortra.
August 13, 2026: Fortra researchers released a report stating their analysis supports ExfilSquad's claims that it holds sensitive data.
What Information Was Compromised?
Our analysis found the following data types in this breach: about 4,036,317 email addresses, about 2,447,926 names, about 371,175 phone numbers, and about 4,889 street addresses.
The Fortra report describes the leaked data as consistent with Microsoft Dynamics 365 exports, including significant personal information, employee and customer contact details, authentication data, password hashes, portal identities, corporate account information, business leads, facilities management records, internal service tickets, and access permissions. Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Exposed email addresses and names can be used for targeted phishing, in which scammers pose as Microsoft, employers, or service providers to trick people into handing over passwords or payment details. Because the leaked set reportedly includes authentication data and password hashes, any reused passwords tied to these accounts should be treated as at risk. Contact details such as phone numbers and street addresses can also support convincing phone scams and identity-related fraud. People whose business records, service tickets, or account information appeared in the leak may face follow-up scams that reference real details to appear legitimate.
What Is Microsoft Doing in Response?
Microsoft has not issued a public statement or breach notification about the alleged incident as of September 25, 2026, based on the most recent reporting we reviewed. Cybersecurity Dive reported that representatives for Microsoft were not immediately available for comment. Separately, the security research firm Starknex, which studied the underlying Power Pages and Dataverse exposure, said it disclosed the configuration issue to Microsoft and other affected organizations. Starknex emphasized the exposure was a configuration problem on individual customer deployments, not a single vendor bug, and reported that most affected sites it tracked had stopped returning exposed records by August 10, 2026, though roughly 30 percent remained vulnerable.
What Should You Do If You Were Affected?
If you believe your information may be in this breach, take these steps:
Watch for phishing emails or calls that mention Microsoft, your employer, or a service account, and never click links or share codes from unsolicited messages.
If you use a Microsoft account or any account connected to a Dynamics 365 service, change your password and enable multi-factor authentication.
Do not reuse the password from the affected account on other services.
Be cautious with unexpected invoices, support tickets, or business correspondence that reference real details, since scammers may have drawn them from leaked records.
Monitor financial statements and consider a credit monitoring service if your address or other personal details were exposed.
In the news
- Fortra: ExfilSquad: New Data Extortion Group Leaks Microsoft D365 Data, Likely Linked to Misconfigured Power Pagesfortra.com (opens in a new tab)
- Cybersecurity Dive: Researchers confirm breach claims by data-extortion groupcybersecuritydive.com (opens in a new tab)
- CYFIRMA: ExfilSquad's Microsoft Data Breach Claimcyfirma.com (opens in a new tab)
- Starknex: BillGate research on Microsoft Dataverse and Power Pages exposurestarknex.com (opens in a new tab)
