Securityaffairs.Co
ExfilSquad Targets 13 Organizations, Threatens Data Leak via Torrents
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
ExfilSquad, a newly identified cybercriminal group, has targeted 13 organizations across the U.S., UK, and Sweden, threatening to leak stolen data unless a ransom is paid. The group primarily exploits cloud portals for data theft and disseminates the stolen information through torrents. Their recent activities include the compromise of the U.K.'s Police National Legal Database, affecting over 100,000 individuals. The group has set a deadline of August 5, 2026, for negotiations, after which they began sharing torrent files containing sensitive data. Among the victims are Wesco International and the UK Department for Education, with records including personal identifiable information (PII) and other sensitive data. Resecurity is monitoring the situation but has not linked ExfilSquad to any known ransomware groups or nation-state actors. The group reportedly consists of younger individuals drawn to hacking for recognition and power. As of August 7, 2026, the group confirmed their credibility by uploading multiple torrent files.
Key Points: • ExfilSquad has targeted 13 organizations, threatening data leaks unless ransoms are paid. • The group exploits cloud portals and shares stolen data via torrents, affecting sensitive information. • Resecurity has not linked ExfilSquad to known ransomware groups or state actors.