Exfil Squad — Ransomware Profile
ExfilSquad, also written Exfil Squad, is a data-extortion crew whose Tor-based leak site surfaced on 26 July 2026 listing roughly 15 alleged victims in a single day, among them Microsoft, Allstate, Frontier Airlines, Zenith Bank, the UK Department for Education and the Police National Legal Database. The group extorts without deploying ransomware — CybelAngel reported no evidence of malware, lateral movement or an exploited vulnerability — and Fortra, which judged leaked samples genuine, named misconfigured Microsoft Power Pages portals exposing Dynamics 365 records to anonymous access as the leading theory for the thefts. In early August 2026 the crew released caches attributed to 13 of the listed organizations via torrents — roughly 382 GB and 27 million records per Infosecurity Magazine — a step Resecurity said settled early doubts about its credibility.Also tracked as
ExfilSquad
IntelFusions coverage (2)
- New extortion crew claims a Spanish cloud host among 28 victims 2026-07-26 · Ransomware
- New extortion crew claims Microsoft, Allstate and two US cities 2026-07-26 · Ransomware
Recent claimed victims
- District of Columbia Public Schools 2026-07-26
- City of Houston 2026-07-26
- City of Atlanta 2026-07-26
- Analog Devices 2026-07-26
- Allstate 2026-07-26
- Newcastle University 2026-07-26
- Viavi Solutions 2026-07-26
- Frontier Airlines 2026-07-26
- Zenith Bank Plc 2026-07-26
- TaylorMade & Sun Day Red golf 2026-07-26
- Bonava 2026-07-26
- UK Department for Education 2026-07-26
- Police National Legal Database 2026-07-26
- Microsoft 2026-07-26
- Wesco International 2026-07-26
Vendor research
- Dark Web Profile: ExfilSquad SOCRadar
- ExfilSquad: 7 Things Security Teams Need to Know CybelAngel