New ExfilSquad Group Emerges, Leaking Data from Multiple High-Profile Victims
A new cybercrime collective, ExfilSquad, has launched a data-leak site and begun publishing stolen data from over a dozen organizations, including major cities and a prominent airline.

A nascent cybercrime group operating under the moniker ExfilSquad has rapidly established itself by launching a dedicated data-leak site and commencing the public dissemination of sensitive information pilfered from numerous organizations. The group's emergence was marked by claims of compromising over 15 entities in a single day, including the municipal governments of Atlanta and Houston, and the U.K. Department of Education. ExfilSquad's modus operandi appears to be solely focused on data exfiltration and subsequent extortion, aiming to pressure victims into payment by threatening permanent public exposure of their stolen data.
On July 26, the group escalated its tactics by posting links to torrent files containing what researchers have confirmed to be complete archives of the exfiltrated data. This move amplifies the pressure on victims, as the data is now widely accessible and potentially distributed across the internet. ExfilSquad's site explicitly states, "Once your company's data is posted here, it's NEVER leaving the public eye and it will be passed around the internet FOREVER." The group rationalizes its demands by asserting that the requested payment is a "rounding error" compared to the potential litigation costs arising from a data leak.
Among the other named victims are Allstate, the District of Columbia Public Schools, and Wesco International, a supply chain giant. In the case of the D.C. Public Schools, cybersecurity firm Resecurity noted that the attackers, demonstrating a peculiar level of selectivity, avoided leaking children's data, instead releasing only sanitized artifacts. This selective release, while still a breach, contrasts with the typical indiscriminate data dumps seen from other groups.
Newcastle University also confirmed falling victim to ExfilSquad, reporting that approximately 440,000 records, including personal identifiable information (PII) of applicants and students, were accessed. The university stated that an investigation revealed a configuration issue in an admissions system connection as the entry point, and that the unauthorized access has since been remediated. The compromised data was limited to contact information, excluding academic records.
ExfilSquad's attacks frequently target customer relationship management (CRM) and internal case management systems, which often contain a wealth of customer data and PII. The group's activity also extended to Zenith Bank in Nigeria, one of the country's largest financial institutions. However, the bank was later removed from ExfilSquad's leak site, a move that experts suggest could indicate successful negotiation or payment by the victim, though false claims by such groups are not uncommon.
The debut of ExfilSquad occurs against a backdrop of declining ransom payments, particularly for extortion-only attacks. Coveware reported that in the second quarter of 2026, only 15% of victims paid solely due to data theft, a significant drop from the previous quarter. This trend suggests that victims are becoming more resilient or are advised against paying, recognizing that payment does not guarantee data deletion and can even confirm its value to other threat actors.
Frontier Airlines is another high-profile target claimed by ExfilSquad, with the group alleging the theft of 43 gigabytes of data, including PII, customer support records, and flight details. However, the airline's systems may have been compromised by other actors as well, given that exploitable vulnerabilities on its website had previously been disclosed by ethical hackers. This situation highlights the complex threat landscape where multiple attackers might exploit the same or different vulnerabilities within an organization's infrastructure.
Experts caution that paying ransoms does not erase the incident and can lead to repeated extortion if multiple threat actors possess the same data. "As the victim, if you pay for it, you're actually the one confirming this data set has a monetary value, and in some of these mass exploits, we have seen the same data set being circulated, and we have seen the same victims being extorted several times for the same data set because it was exfiltrated due to a widely known vulnerability," stated Magnus Jelen, director of incident response in EMEA for Coveware by Veeam.