2026-09-08
Added
Registered investment advisers and broker-dealers are being warned by the California Department of Financial Protection and Innovation (DFPI) about a significant security threat. This threat involves misconfigured Microsoft Power Pages portals that allow unauthorized access to firm data stored in Microsoft Dynamics 365, which threat actors are exploiting for data extortion campaigns targeting financial services firms. The DFPI recommends firms immediately audit and remediate Power Pages and Dataverse configurations, specifically disabling anonymous access, removing the anonymous users web role from all table permissions, and restricting web access to operationally necessary tables. Firms are also urged to report any cybersecurity incidents to the Department through its Cybersecurity Incident Report Form.
The California Department of Financial Protection and Innovation (DFPI) is warning registered investment advisers and broker-dealers about a significant security threat involving misconfigured Microsoft Power Pages portals that can allow unauthorized access to firm data stored in Microsoft Dynamics 365 (D365).
Threat actors are actively exploiting these misconfigurations to conduct ongoing data extortion campaigns targeting organizations across multiple sectors, including financial services firms. By taking advantage of improper permissions, perpetrators can gain unauthorized access to databases containing customers’ and employees’ personally identifiable information (PII). They then threaten to publicly disclose the compromised data unless customers and employees meet their ransom demands.
It is important to note that this threat does not stem from a vulnerability within Microsoft 365 itself, but rather from misconfigurations in how Power Pages portals and associated permissions are set up.
The DFPI recommends that firms immediately audit and remediate Power Pages and Dataverse configurations to eliminate unauthorized external access. These measures include, but are not limited to, disabling anonymous access, removing the anonymous users web role from all table permissions, and restricting web access to only those tables that are operationally necessary. The “anonymous user” role in Microsoft 365 represents unauthenticated external users who can access shared resources without signing in with a Microsoft account. Firms should refer to Microsoft’s Power Pages Security Documentation for detailed implementation guidance.
The DFPI urges firms to report any cybersecurity incidents to the Department through our Cybersecurity Incident Report Form .
More like this from DFPI
DFPI published 2 documents in the last 30 days. We email you each new one the day it's published.