Exfil Squad — Ransomware Profile

ExfilSquad, also written Exfil Squad, is a data-extortion crew whose Tor-based leak site surfaced on 26 July 2026 listing roughly 15 alleged victims in a single day, among them Microsoft, Allstate, Frontier Airlines, Zenith Bank, the UK Department for Education and the Police National Legal Database. The group extorts without deploying ransomware — CybelAngel reported no evidence of malware, lateral movement or an exploited vulnerability — and Fortra, which judged leaked samples genuine, named misconfigured Microsoft Power Pages portals exposing Dynamics 365 records to anonymous access as the leading theory for the thefts. In early August 2026 the crew released caches attributed to 13 of the listed organizations via torrents — roughly 382 GB and 27 million records per Infosecurity Magazine — a step Resecurity said settled early doubts about its credibility.

Also tracked as

ExfilSquad

IntelFusions coverage (2)

Recent claimed victims

Vendor research

Read the full analysis on IntelFusions