New extortion crew claims Microsoft, Allstate and two US cities

A previously unrecorded extortion brand calling itself Exfil Squad surfaced on 26 July 2026 and immediately posted 14 organizations to its data-leak site, including Microsoft, the US insurer Allstate, Frontier Airlines, and the city governments of Atlanta and Houston. Every one of those claims is unverified, and no named organization has confirmed a breach.

IntelFusions leak-site monitoring recorded all 14 listings appearing on the same day, which is the group's first recorded activity of any kind. That is an unusual debut. Established crews accumulate a victim list over weeks, while a wall of household names posted at once is a pattern seen most often when a new brand is trying to buy credibility quickly.

What the group is claiming

The listings are notable less for the names than for the volumes attached to them. Exfil Squad's own posts claim roughly 6 million records from the City of Houston, about 3 million from the City of Atlanta, around 2 million from golf equipment maker TaylorMade and its Sun Day Red brand, roughly 842,000 from Swedish homebuilder Bonava, and about 430,000 from network test firm Viavi Solutions. The rest of the list runs across sectors and borders: the UK Department for Education, the Police National Legal Database, Newcastle University, District of Columbia Public Schools, Nigeria's Zenith Bank, and semiconductor maker Analog Devices.

Nothing in the postings claims file encryption or operational disruption. This is straight data-theft extortion, the model that has steadily displaced encryption-first ransomware, and the same pressure tactic behind the claims against Abbott earlier this month.

Why the list deserves skepticism

Read the descriptions side by side and they describe strikingly similar material: citizen service requests, complaint text, case and ticket metadata, department routing, support history, order and shipping records, and in one case AI support chat transcripts. That is customer service and CRM data, not the mixed file shares a network intrusion usually yields.

Uniformity like that is a signal. When a dozen unrelated victims all lose the same shape of data at the same moment, the likelier explanation is one shared platform or service provider rather than 14 separate break-ins. IntelFusions has not identified such a platform and Exfil Squad has not named one, so this remains an assessment rather than a finding. An alternative reading, equally consistent with a debut of this shape, is that some datasets are recycled from older breaches and repackaged under a new banner, a habit documented among the smaller brands crowding the leak sites this month.

What you should do

Treat every entry as an allegation until the organization or a regulator says otherwise, and do not repeat the record counts as fact, because the numbers come from the extortionists. Organizations that recognise their own data in the descriptions should start with third-party access rather than the perimeter: inventory which SaaS helpdesk, CRM and support-ticket platforms hold customer records, review the integration tokens and OAuth grants attached to them, and pull access logs for bulk export activity over the past 90 days.

Support-desk data is unusually dangerous once leaked, because it pairs verified contact details with the context of a real prior conversation. Expect follow-on phishing and voice phishing that references genuine ticket numbers, and brief service-desk staff accordingly. Watch the group's tracked activity for whether it follows through and publishes data or quietly disappears, which is itself the clearest test of whether these claims were ever real.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions