ExfilSquad, an emerging data-extortion operation, reportedly breached exposed cloud, CRM, case-management and Microsoft Power Pages data sources belonging to UK public-sector, education and law-enforcement organizations, as well as companies worldwide. Reported victims include the UK Department for Education, the Police National Legal Database and Newcastle University; the alleged thefts exposed hundreds of thousands of contact and personal-data records.
Rather than deploying ransomware to encrypt systems, the group threatens to publish stolen data through a Tor-based leak site. It distributes victim-specific, multi-gigabyte leaks through torrents using separate trackers and web seeds, making takedown and containment more difficult and increasing downstream risks of phishing, social engineering and threats to affected individuals' physical security.

See attribution, scope, and your downstream exposure.
6 events from the most recent confirmed update back to the earliest known activity.
On July 26, 2026, ExfilSquad publicly emerged with a Tor-hosted leak site and published 15 alleged victim listings in a single day, including Microsoft, Newcastle University, the Police National Legal Database, and the UK Department for Education. The claims were not accompanied by forensic evidence, verifiable data samples, or independent confirmation; on July 27, the group posted an unverified purported Microsoft directory-record screenshot on X.
ExfilSquad reportedly uploaded multi-gigabyte victim-specific torrent files to its Tor-based leak site to substantiate extortion claims. Resecurity reported that the group assigned each victim a distinct torrent tracker and initial web seed, aiding peer-to-peer distribution of leaked data.
Newcastle University confirmed a potential unauthorized data-access incident linked to ExfilSquad. The incident reportedly exposed about 440,000 applicant and student records, with a configuration flaw in an admissions-system connection cited as the cause.
The Police National Legal Database confirmed a breach linked to ExfilSquad involving reportedly 1.9 GB of data and roughly 135,000 records. The data allegedly included contact details for more than 100,000 police, staff, and criminal-justice professionals and about 21,000 Ask the Police inquiry records.
The UK Department for Education confirmed a breach linked to ExfilSquad. The reported exposure included about 600,000 Help Portal records and about 7,000 Turing Portal records containing parent and staff contact and job information.
In mid-2026, the emerging ExfilSquad group reportedly targeted UK public-sector, education, and law-enforcement organizations, as well as other organizations worldwide. The group allegedly exploited exposed cloud portals, CRM, case-management, and Microsoft Power Pages data sources and threatened to publish stolen data rather than deploying file-encrypting malware.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
8 references tracked. Mallory keeps watching after this page renders.
infosec.pub
Open sourcemalware.news
Open sourceblog.bushidotoken.net
Open sourcepnld.co.uk
Open sourcesocradar.io
Open sourceransomware.live
Open sourcesans.org
Open sourcethetimes.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.