Threat Intelligence

ExfilSquad targets 13 organizations, uses torrents for data distribution

Hacked computer system showing a skull icon with lines of code, illustrating cybercrime, data protection issues, and malware

ExfilSquad, a cybercrime group that emerged in mid-2026, has announced 13 new victim organizations across the U.S., UK, and Sweden, with further coverage provided by Security Affairs.

The group, which extorts victims by threatening to publish stolen data rather than using ransomware, has expanded its operations, according to a recent report by Resecurity. In July, ExfilSquad targeted a major financial institution in Nigeria and recently set a deadline of August 5, 2026, for negotiations with its latest victims. Their tactics involve exploiting cloud portals, including misconfigured Microsoft Dataverse, Power Pages, and CRMs, for large-scale data theft. Notably, ExfilSquad gained attention after a cyberattack on the UK's Police National Legal Database, compromising data of over 100,000 individuals.

To amplify damage, the group leverages P2P networks and torrent files for data distribution, a method also seen with LockBit 3.0 and Cl0p ransomware. This approach makes data widely accessible and difficult to remove, increasing reputational and financial damage to victim organizations.

Source: Security Affairs

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds