ExfilSquad is a cybercriminal data-extortion group that emerged publicly in July 2026. It is also known as exfil_squad. The group steals data from exposed enterprise and public-sector environments and demands payment under threat of public release, rather than deploying file-encrypting ransomware. It operates a leak site and has distributed victim data through torrent-based peer-to-peer distribution, increasing the difficulty of containment after publication. ExfilSquad has been linked to incidents affecting government and public-sector entities, educational institutions, financial-services organizations, and industrial firms, principally in the United Kingdom and United States. Confirmed or publicly acknowledged incidents associated with its activity include unauthorized-access events involving Newcastle University, the UK Department for Education, the UK Police National Legal Database, and Wesco. Publicly released data associated with the operation has been independently assessed as credible for multiple claimed victims. The group’s principal assessed intrusion method is abuse of misconfigured Microsoft Power Pages portals connected to Microsoft Dataverse, Dynamics 365 CRM, or ERP environments. Overly permissive anonymous table-read permissions can enable unauthenticated querying and bulk extraction of exposed data through Power Pages web APIs. Automated scanning and enumeration of public-facing Power Pages deployments have been associated with this activity. Available reporting does not substantiate exploitation of a Microsoft Dynamics 365 software vulnerability, deployment of malware, lateral movement, or ransomware encryption by ExfilSquad. ExfilSquad’s extortion activity commonly involves public victim naming, release deadlines, and publication of purported customer, employee, student, applicant, administrative, and law-enforcement contact data. Exposure of such data creates material follow-on risks of targeted phishing, impersonation, and social-engineering attacks.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
19 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
ExfilSquad is identified as an emerging cybercrime group; no operational, targeting, or tooling details are provided.
A pure data-extortion group conducting large-scale theft from publicly exposed or misconfigured cloud portals, CRM platforms, case-management systems, and Microsoft Power Pages tables. It threatens to publish stolen data through an onion-hosted leak site and distributes victim-specific multi-gigabyte torrent files using distinct torrent trackers and web seeds.
A pure data-extortion group that steals data from exposed cloud/SaaS portals and threatens publication on its Tor-based data leak site rather than deploying file-encrypting ransomware. Its reported victims include the UK Department for Education, Police National Legal Database, and Newcastle University.
Groupe d'extorsion ayant revendiqué, sans preuve vérifiée, le vol de 570 000 enregistrements à Analog Devices.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.