2026-09-08

Added

Threat Actors Exploiting Microsoft 365 Power Pages Misconfigurations to Target Financial Services Firms

Registered investment advisers and broker-dealers are being warned by the California Department of Financial Protection and Innovation (DFPI) about a significant security threat. This threat involves misconfigured Microsoft Power Pages portals that allow unauthorized access to firm data stored in Microsoft Dynamics 365, which threat actors are exploiting for data extortion campaigns targeting financial services firms. The DFPI recommends firms immediately audit and remediate Power Pages and Dataverse configurations, specifically disabling anonymous access, removing the anonymous users web role from all table permissions, and restricting web access to operationally necessary tables. Firms are also urged to report any cybersecurity incidents to the Department through its Cybersecurity Incident Report Form.

California Department of Financial Protection and Innovation logo

California

California Department of Financial Protection and Innovation

Click to view full text

More like this from DFPI

DFPI published 2 documents in the last 30 days. We email you each new one the day it's published.

Topics
Share