ExfilSquad is a cybercrime data-extortion group that emerged in mid-2026 and is associated with hack-and-leak operations against organizations in government, education, financial services, manufacturing, and other sectors. Rather than deploying ransomware encryption, the group steals data and pressures victims to pay by threatening public release on a leak site, and in multiple cases has distributed victim data through torrent-based peer-to-peer channels to increase dissemination and complicate takedown. ExfilSquad has been linked to at least 13 publicly leaked victim datasets and initially claimed compromises affecting 15 organizations. Reported victims include public-sector and education entities such as the UK Department for Education, the UK Police National Legal Database, District of Columbia Public Schools, the City of Atlanta, and Newcastle University, as well as private-sector organizations including Wesco. Public reporting also places additional victims in the United States, United Kingdom, Sweden, and Nigeria. The group’s activity is strongly associated with unauthorized access to cloud and SaaS business platforms, especially Microsoft Dynamics 365-related environments, Microsoft Dataverse, Power Pages portals, and CRM or case-management systems. Multiple analyses assessed that ExfilSquad likely exploited exposed or misconfigured public-facing portals that allowed anonymous or overly broad read access to backend data, enabling large-scale collection and exfiltration without malware deployment. Reported tradecraft includes exploiting public-facing applications, collecting data from cloud storage, and exfiltrating data over web services. Researchers also assessed that victim discovery likely involved internet-scale enumeration or crawling for exposed portals. ExfilSquad’s operations center on data theft, publication threats, and reputational pressure. The group has published sample data to substantiate claims, imposed negotiation deadlines, and released full or partial datasets when demands were not met. In several incidents, victim organizations stated there was no evidence of ransomware or broader malware on internal systems, reinforcing the assessment that ExfilSquad specializes in data-theft extortion rather than network encryption campaigns. Known aliases are limited to ExfilSquad.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only in related article links, not part of the main incident.
Data extortion campaign involving exfiltration and public release of victim data via torrents, likely by identifying and abusing publicly exposed Microsoft D365 CRM/ERP data through misconfigured Microsoft Power Pages portals.
Claimed responsibility for the breach of England's Department for Education and reportedly published or advertised stolen data online after the intrusion.
Data extortion campaign involving exfiltration and public release of stolen data from at least 13 victims after alleged failure to meet the group's demands. The activity is assessed as likely involving unauthorized read access to Microsoft D365 CRM/ERP data via misconfigured Microsoft Power Pages portals and related enumeration/scanning for exposed instances.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.