戻る

ExfilSquad Targets New Victims, Shares Data via Torrents

Cyber Threat Intelligence

TOR, DLS, Ransomware, Hacking, Data Breach

ExfilSquad Targets New Victims, Shares Data via Torrents
ExfilSquad Targets New Victims, Shares Data via Torrents

Introduction

ExfilSquad is an emerging cybercriminal hacking group identified in mid-2026 as responsible for high-profile data breaches. Notably, the group does not typically deploy ransomware or destructive malware; instead, they threaten to leak stolen data on a dedicated onion-based Data Leak Site (DLS) unless a ransom is paid. 

ExfilSquad announced new victims this week and set a firm deadline - August 5, 2026 - to complete all required negotiations. Otherwise, the stolen data will be released. This time, the list of victims includes 13 organizations from the U.S., the UK, and Sweden. Notably, in July, the group was also targeting a major financial institution in Nigeria.


The collective attracted attention after the cyberattack on the U.K.'s Police National Legal Database (PNLD), which compromised contact data of more than 100,000 police officers and criminal justice professionals.

Who are ExfilSquad Members?

In a recent interview with one of the ExfilSquad representatives, it was suggested that teenagers may be involved in the group's activities. According to the materials released by The Times, "A lot of teens are drawn to hacking because it feels like a game — you get recognition, a sense of identity, community, and a lot of power." 

The group's member also added that, in some cases, they targeted Microsoft Power Pages data tables, which were not properly protected. According to him, the group’s members met online through various hacker circles and forums.

At this stage, Resecurity does not link the group to any previously known ransomware conglomerate or nation-state actor. Collectives like ExfilSquad follow a pattern observed in other "squads," responsible for large-scale data breaches, where the actors are both having "fun" and targeting high-profile entities for extortion.

At some point, after a successful compromise, the group suggests that the victim should be punished for their lack of cybersecurity and that they should invest more effort in it when providing services or solutions to their own customers, who may be impacted by such negligence.

New Victims Announced

Notably, on August 6, 2026, the group was very busy, and some of the shared samples containing leaked data were unavailable. Cybersecurity professionals have begun to question whether the group was merely speculating or preparing to extort some of the world's major organizations. 

However, the next day, August 7, 2026, the group uploaded multiple torrent files for each victim, thereby proving their credibility. ExfilSquad has announced multiple victims, including but not limited to:

Wesco International

2.6M~ records containing: customer and employee PII, account and contact data, CRM user profiles, credit and business identifiers, authentication metadata, and access information.

UK Department for Education (education.gov.uk)

Help Portal (~600K records) – Parent and staff contact records containing full names, email addresses, phone numbers, and job titles.
Turing Portal (~7K records) – Contact records containing full names, email addresses, phone numbers, and job titles.

Police National Legal Database (UK PNLD)

135k law enforcement contact records with first/last name, email, police force area, etc.

Allstate

657K~ records containing: significant PII, recruitment and licensing information, onboarding data, and internal employee account information.

TaylorMade & Sun Day Red Golf

2M~ records containing: significant PII, customer support history, orders, shipping information, business account data, financial/account information, internal notes, attachments, and AI support chat transcripts.

Frontier Airlines

2.4M~ records containing: significant PII, customer support cases, flight and travel information, complaint records, baggage details, and customer support email communications.

District of Columbia Public Schools (dcps.dc.gov)

60K~ records containing: students names, dates of birth, home addresses, phone numbers, unique student identifiers, school assignments, grade levels, registration status information.

Newcastle University (ncl.ac.uk)

440K~ records containing: applicant and student contact information, significant PII, and admissions data.

Viavi Solutions

430K~ records containing: customer and partner contact information, significant PII, and enterprise account identifiers.

City of Houston

6M~ records containing: significant PII, resident contact details, service requests, complaint descriptions, addresses, location data, case/ticket metadata, department routing, service status, resolution information, and extensive CRM metadata.

City of Atlanta
3M~ records containing: significant PII, citizen service requests, addresses, municipal case history, and internal case management data.

Bonava
842K~ records containing: significant PII, property ownership/interests, warranty and repair cases, contractor information, marketing preferences, and customer service history.

Interestingly, in the case of the District of Columbia Public Schools (DCPS) system breach, the actors demonstrated a certain level of ethics and did not leak children's data. The leaked data included only sanitized artifacts for specific records.

The notable pattern is the strong targeting of CRM, internal case management systems, and AI platforms used to collaborate with consumers. Such systems often process massive volumes of information received via customer support, analyzing tickets and providing automated responses. Resecurity covered the threats posed by AI-enabled assistants in one of our recent reports (Cybercriminals Are Targeting AI Agents and Conversational Platforms: Emerging Risks for Businesses and Consumers).

Several victims referenced compromised CRM metadata, which may reveal substantial information about customers and their PII. One of the most notable data breaches involved the City of Houston (houstontx.gov) and the City of Atlanta (atlantaga.gov), which were likely targeted via one of these systems exposing resident information.

This threat intelligence report by Resecurity is not focused on a specific victim or the scope of its compromise, but rather on the ExfilSquad's TTPs and the motives behind this activity. By understanding them, cybersecurity professionals can increase their awareness of ExilSquad activities and protect their systems more effectively.

About a week ago, on July 26, 2026, ExfilSquad claimed to have breached Zenith Bank (Nigeria), allegedly stealing around 90 million records totaling 874 GB. The stolen data reportedly included PII, account and financial information, government identifiers, customer contacts, and banking support records. 

However, as of August 7, 2026, all claims regarding this bank have been removed from their DLS. It is not clear whether the actors received payment from the victim or if there were other reasons for that. The bank has publicly acknowledged an investigation into a possible cybersecurity incident:

Resecurity can confirm that at least two other victims were involved in possible ongoing negotiations with the actors. Still, the outcomes of those negotiations remain unknown or unsuccessful, which likely triggered the publication of the stolen data.

Torrent Renaissance

Each of the victims published on their Data Leak Site (DLS) in TOR also had a reference to a torrent file for download—enabling the circulation of stolen data via P2P. By using torrents, ransomware actors ensure that the leaked data is easily accessible to a broader audience, including journalists, researchers, and other malicious actors. This amplifies the reputational damage to victims, as the data becomes widely available and harder to control.

Such an approach has already been used by other extortion groups, for example, LockBit 3.0 and Cl0p Ransomware. For instance, they have utilized URLs generated within the TOR network and leveraging the Onion Protocol, as well as sharing links via the surface web. However, due to DDoS attempts aimed at preventing data publication, these methods experienced outages and extremely slow speeds. 

After some time, the actors pivoted to releasing data via torrents to enable faster peer-to-peer transfer. Cl0p has created torrents for over 20 victims, including Aon, K&L Gates, Putnam, Delaware Life, and Zurich Brazil, which resulted in substantial damage. Such an approach is also used by independent actors when extorting victims, demonstrating that the stolen data cannot be deleted and that the only reasonable course of action is to negotiate and arrange a ransom payment to prevent the leak.

Once stolen data has been released, it is not possible to stop its sharing via the P2P network or remove the torrent file, because other participants involved in seeding can easily resume downloads. Resecurity views this tactic as a trend leveraged by multiple sophisticated actors involved in hack-and-leak operations.

Resecurity analyzed the nodes involved in torrent sharing, as well as seeds that participated in the circulation of stolen data. Interestingly, hosts from China and Russia were among the most active during August 7, 2026, which may suggest that the operators behind them had prior knowledge of the data publication or were involved in its distribution at a later stage once it became available. In any case, such hosts indicate an interest in this type of data.

The number of hosts from both geographies increased to 16 by 11 a.m. PDT on August 7, 2026

Resecurity detected over 50 seeds appearing at different times later. These hosts are unlikely to be directly associated with the actors but could be involved in the download of compromised data and subsequent analysis by independent researchers, including the end victims.

Resecurity also documented the infrastructure of torrent trackers used to share stolen data. Notably, some of them are managed in the US and EU, with the latter subject to significant regulatory oversight of data breaches under the GDPR. At the same time, this did not prevent torrents operating within the EU from making such information available for download and further distribution. 

This phenomenon could be explained by the nature of P2P communications, which involve multiple parties acting as "peers" — facilitating data sharing once at least one participant has downloaded it. Notably, ExfilSquad used many diverse Torrent Trackers, unlike other ransomware operators who typically rely on just one. This approach makes their operations large-scale and more difficult to track. According to a Resecurity assessment, each victim is assigned a unique Torrent Tracker and an initial Web Seed, which is a notable tactic employed by the hacking collective. 

This approach makes their operations large-scale and more difficult to track. According to a Resecurity assessment, each victim is assigned a unique Torrent Tracker and an initial Web Seed, which is a notable tactic employed by the hacking collective.

Significance

ExfilSquad is a rapidly emerging, financially motivated data extortion group whose TTPs revolve around exploiting misconfigured cloud/SaaS portals for large-scale data theft and extortion. They have targeted a diverse set of high-profile organizations across multiple countries and sectors. Their operations are characterized by technical sophistication in cloud exploitation and aggressive public extortion tactics.

Resecurity recommends organizations conduct ongoing Vulnerability Assessment and Penetration Testing (VAPT) to ensure possible misconfigurations are identified before adversaries can exploit them. Additionally, they advise strengthening access controls to CRM systems, employee portals, and consumer-facing portals that store sensitive PII and other records.

ニュースレター

最新のサイバーセキュリティニュースと動向をチェックしましょう。

購読することで、プライバシーおよびクッキーポリシーに従って、私の個人データが収集・処理されることに同意します。

クラウドアーキテクチャ
クラウドアーキテクチャ
445 S. Figueroa Street
Los Angeles, CA 90071
Googleマップ
フォームにご記入のうえ、お問い合わせください
今すぐResecurity製品を無料トライアルでお試しください
Resecurity
閉じる
こんにちは!ご質問にお答えし、お手伝いするためにここにいます。
始める前に、お名前とメールアドレスをご提供いただけますか?