ExfilSquad, also known as Exfil Squad and exfil_squad, is a financially motivated cybercriminal group conducting data-theft extortion. It publicly emerged on July 26, 2026, with a Tor-hosted data-leak site and claims involving 15 organizations. Its operations target government, education, law enforcement, financial services, technology, manufacturing, retail, transportation, and real estate organizations, with documented data disclosures involving organizations in the United States, United Kingdom, and Sweden. The group abuses misconfigured cloud and SaaS business applications, particularly Microsoft Power Pages portals connected to Dynamics 365 and Dataverse. Overly permissive table permissions assigned to the Anonymous Users web role can allow unauthenticated visitors to query and extract sensitive information through exposed web APIs. Its campaigns focus on CRM, customer-support, admissions, and case-management data. This activity involves unauthorized access enabled by configuration weaknesses rather than a demonstrated vulnerability in Dynamics 365. Newcastle University confirmed that a configuration flaw in a connection to an admissions system exposed personal contact information. ExfilSquad pressures victims through public naming, payment deadlines, and threats to publish stolen information. Its established model is encryption-less data extortion; file-encrypting ransomware deployment has not been confirmed. On August 7, 2026, the group released torrent-based datasets for 13 organizations, totaling approximately 382.64 GB of uncompressed data and 27 million records. Independent examination substantiated its possession of sensitive victim data. The disclosures included personal information, customer and employee records, municipal service requests, student information, and law-enforcement contacts. Victim-specific torrent trackers and web seeds facilitate peer-to-peer dissemination and complicate containment. Confirmed affected organizations include the UK Department for Education, the Police National Legal Database, and Newcastle University.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
19 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a historical comparison for data-extortion threats against UK organizations, not as an attributed participant in the ASOS incident. The access techniques are discussed collectively rather than tied to a specific ExfilSquad operation.
ExfilSquad is identified as an emerging cybercrime group; no operational, targeting, or tooling details are provided.
A pure data-extortion group conducting large-scale theft from publicly exposed or misconfigured cloud portals, CRM platforms, case-management systems, and Microsoft Power Pages tables. It threatens to publish stolen data through an onion-hosted leak site and distributes victim-specific multi-gigabyte torrent files using distinct torrent trackers and web seeds.
A pure data-extortion group that steals data from exposed cloud/SaaS portals and threatens publication on its Tor-based data leak site rather than deploying file-encrypting ransomware. Its reported victims include the UK Department for Education, Police National Legal Database, and Newcastle University.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.