ExfilSquad, a cybercrime group that emerged in mid-2026, has announced 13 new victim organizations across the U.S., UK, and Sweden, with further coverage provided by Security Affairs.The group, which extorts victims by threatening to publish stolen data rather than using ransomware, has expanded its operations, according to a recent report by Resecurity. In July, ExfilSquad targeted a major financial institution in Nigeria and recently set a deadline of August 5, 2026, for negotiations with its latest victims. Their tactics involve exploiting cloud portals, including misconfigured Microsoft Dataverse, Power Pages, and CRMs, for large-scale data theft. Notably, ExfilSquad gained attention after a cyberattack on the UK's Police National Legal Database, compromising data of over 100,000 individuals.To amplify damage, the group leverages P2P networks and torrent files for data distribution, a method also seen with LockBit 3.0 and Cl0p ransomware. This approach makes data widely accessible and difficult to remove, increasing reputational and financial damage to victim organizations.Source: Security Affairs
Threat Intelligence
ExfilSquad targets 13 organizations, uses torrents for data distribution
(Adobe Stock)
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
