SYS::ONLINE
Wasteland.
Briefs1902
Issues23
SinceFeb 2026
LIVE
▣ Breach EXFILSQUAD-13-VICT 2026-08-13

Wesco, PNLD and Analog Devices: ExfilSquad Torrent Leak Campaign

"ExfilSquad, a data extortion crew that surfaced in mid-2026, has named a fresh batch of victim organizations across the United States, United Kingdom and Sweden, and is now seeding the stolen archives over BitTorrent…"

ExfilSquad, a data extortion crew that surfaced in mid-2026, has named a fresh batch of victim organizations across the United States, United Kingdom and Sweden, and is now seeding the stolen archives over BitTorrent rather than gating them behind a Tor leak site. SC Media, citing research by Resecurity and with corroborating coverage from Security Affairs, puts the count at 13 organizations in this round. Counts for the group's earlier debut differ: CybelAngel, drawing on reporting from Protos, describes an opening leak-site post on July 26, 2026 naming roughly 15 alleged victims across five countries. Two of the named organizations, Wesco International and the UK's Police National Legal Database, have publicly confirmed incidents; a third, Analog Devices, disclosed a breach to the SEC while explicitly declining to link it to the group's claims.

What Happened

ExtilSquad's operating model is theft and blackmail without encryption. SC Media reports the group extorts victims by threatening publication of stolen data rather than deploying ransomware, and SecurityWeek makes the same assessment independently. The crew set an August 5, 2026 negotiation deadline for its latest tranche of victims, a date also reported by CybelAngel via The Times.

The confirmed cases break down as follows:

Police National Legal Database (UK). The intrusion was detected Sunday, July 26 and later claimed by ExfilSquad. PNLD is the legal reference service used for more than 30 years by all 43 Home Office police forces in England and Wales plus the British Transport Police, and it hosts the public-facing Ask the Police site. PNLD confirmed in a statement that contact data was compromised and published on the dark web. The National Crime Agency is assisting the investigation and the Information Commissioner's Office has been notified.

Wesco International (US). The Fortune 500 distributor, roughly 21,000 employees, 700-plus facilities in about 50 countries and around $24 billion in annual sales, confirmed to BleepingComputer on August 11 that it is investigating an incident affecting its cloud CRM environment. Jennifer Sniderman, VP of Corporate Communications, said Wesco worked with its cloud CRM vendor and does not believe sensitive data is at risk. The company reported no business disruption and no evidence of ransomware or other malware on its IT systems.

Analog Devices (US). The Massachusetts chipmaker, about 24,000 employees and $12 billion in revenue, told the SEC it identified unauthorized access on June 23, 2026 and that certain files were exfiltrated. Critically, the 8-K treats the ExfilSquad claim as a separate matter: the filing states that "separately and unrelated, on July 26, 2026, the Company was made aware of public reports regarding a disparate cybersecurity matter and is currently assessing its validity, scope, and any potential impact." SecurityWeek notes ADI later disappeared from the group's leak site.

Department for Education (UK). Computer Weekly, following The Times, reports a social engineering attack against an internal helpdesk used by school, university and local authority staff. DfE has pulled several systems offline and is engaged with the ICO, NCA and NCSC.

Accounts genuinely differ on the scope of the group's victim list. The leak site has at various points listed Microsoft, Allstate, and the cities of Atlanta and Houston. Computer Weekly describes the claimed Microsoft breach as "alleged, unconfirmed," and SecurityWeek reports that SOCRadar assessed some of the group's claims as exaggerated or fabricated. Treat the leak-site roster as a claim, not a victim count.

What Was Taken

Figures vary by source and by whether they come from the victim or the extortionist.

PNLD: BleepingComputer reports contact data of more than 100,000 police officers and criminal justice professionals compromised, while ExfilSquad itself claims 135,000 records totalling 1.9 GB. Security Affairs adds a third reference point, noting PNLD recorded 108,429 police registrations in its 2025-26 annual summary, while stressing that PNLD has not disclosed how many individuals are actually in the breached dataset. Exposed fields per the PNLD notice: full names, organisations and work email addresses of officers, staff, criminal justice professionals, government partners and customers, plus names and email addresses of members of the public who submitted questions to Ask the Police. PNLD says there is no evidence passwords or security credentials were compromised, and that it holds no confidential data on victims, witnesses or offenders.

Wesco: ExfilSquad claims 2.6 million records covering customer and employee PII, account and contact data, CRM user profiles, and credit and business identifiers. Wesco's own statement contradicts the severity, saying it does not believe payment card information, financial account information or other sensitive customer or employee data is at risk. That is an unresolved conflict between actor claim and victim assessment.

Department for Education: more than 600,000 records per The Times as relayed by Computer Weekly, comprising full names, email addresses and phone numbers of government and university staff and senior school officials including headteachers. The DfE spokesperson characterised the exposure narrowly: "The information involved is limited to customer service contact details relating to individuals and organisations. No other data has been accessed."

Analog Devices: ExfilSquad claims 570,000 records. ADI's SEC filing confirms only that "certain files were exfiltrated" and says the scope investigation is ongoing, adding that to its knowledge the data has not been publicly released or used fraudulently.

The pattern across confirmed cases is contact-tier PII rather than credentials or payment data. That is lower-severity per record, but it is precisely the fuel for the next round of social engineering.

Why It Matters

The BitTorrent distribution is the escalation worth planning around. SC Media reports the group uses P2P networks and torrent files to publish stolen data, a technique previously used by LockBit 3.0 and Cl0p. Once a torrent is seeded and swarming, takedown notices to a hosting provider stop working. There is no single server to seize, no dark web mirror to disrupt, and no realistic path to making the data unavailable again. For a victim weighing whether to pay, this changes the calculus: the leverage is not "we will publish" but "we will make it permanent."

Second, this is an identity and third-party problem, not a malware problem. Wesco found no ransomware or malicious software on its systems and still lost CRM data. ADI's operations were never interrupted. CybelAngel's summary of the campaign is blunt on this point: no exploit written, no malware involved, no password cracked. Detection stacks tuned for encryption events and payload execution will see nothing.

Third, the PNLD exposure carries downstream risk that record counts understate. Security Affairs identifies two distinct victim classes: named officers who are now materially more exposed to targeted phishing, and members of the public whose contact with police services is now a matter of public record. ESET's Jake Moore, quoted in Computer Weekly, framed the broader risk as attackers "piecing together a data jigsaw" to build convincing follow-up phishing.

Finally, verify before you panic. SOCRadar's assessment that some claims appear exaggerated or fabricated, ADI's removal from the leak site, and the unconfirmed Microsoft claim all point the same direction: this group's public list is a marketing document.

The Attack Technique

Per Resecurity's research as reported by SC Media, ExfilSquad's core tradecraft is the exploitation of misconfigured cloud portals, specifically naming Microsoft Dataverse, Power Pages, and CRM platforms, for large-scale data theft. Wesco's confirmation that its incident involved the cloud CRM environment, and that it worked the matter with its cloud CRM vendor, is consistent with that pattern.

The second vector is human. Computer Weekly reports the DfE compromise came through a social engineering attack against an internal helpdesk serving school, university and local authority staff, the classic helpdesk-impersonation route to account access.

SC Media also notes the group hit a major financial institution in Nigeria in July, indicating targeting broader than the US, UK and Sweden footprint of the current tranche. The Times assesses the motive as financial rather than political.

What Organizations Should Do

  1. Audit Power Pages and Dataverse exposure now. Enumerate every Power Pages site and Dataverse table with anonymous or broadly-scoped table permissions. Misconfigured web roles that grant read access to contact and account tables are the specific failure mode Resecurity flags. Treat "authenticated users" as a public audience unless you have verified who can self-register.

  2. Treat the CRM as crown-jewel data. Enforce phishing-resistant MFA on every CRM and SaaS admin account, and audit OAuth application grants and long-lived API tokens against those tenants. Wesco lost CRM data with no malware anywhere on its network; endpoint controls do not cover this.

  3. Harden the helpdesk against identity resets. The DfE vector was social engineering against internal support staff. Require out-of-band verification for password and MFA resets, ban knowledge-based authentication using data that may already be leaked, and add callback verification for any privileged account change.

  4. Instrument for bulk read, not just exfiltration. Alert on anomalous export volume, unusual API query rates against contact and account objects, and first-time-seen report generation. These attacks look like a busy sales rep in the logs unless you baseline volume.

  5. Assume permanence in your incident response plan. With torrent distribution, "contain the leak" is not an achievable objective. Shift planning toward notification speed, credential and identifier rotation where applicable, and sustained phishing defence for affected individuals.

  6. Pre-brief high-risk staff on follow-on phishing. Where contact-tier PII is exposed, the exposure converts directly into targeted lures. Named officers, headteachers and finance staff should be warned specifically, with a clear internal channel for reporting suspicious approaches.

  7. Validate any leak-site claim naming your organisation before responding publicly. Given SOCRadar's finding of exaggerated or fabricated entries, confirm through your own telemetry and vendor logs before conceding scope in a statement.

Sources: ExfilSquad targets 13 organizations, uses torrents for data distrib... | ExfilSquad hackers leak info of over 100,000 UK police officers, staff | Department for Education suffers data breach Computer Weekly | Wesco confirms security incident after ExfilSquad claims data theft | PNLD Confirms Data Breach Affecting UK Police and Justice Staff | Semiconductor Firm Analog Devices Discloses Data Breach - SecurityWeek | Analog Devices Discloses Data Breach After Unauthorized System Acce... | ExfilSquad: 7 Things Security Teams Need to Know