A previously unknown data extortion group calling itself ExfilSquad surfaced on July 26, 2026 with a Tor-hosted leak site and roughly 15 named victims posted in a single burst, among them the municipal governments of Atlanta and Houston, Frontier Airlines, Microsoft, Allstate, Analog Devices, Wesco International and the District of Columbia Public Schools. On Friday the group escalated from claims to distribution, posting torrent links to what researchers say appear to be complete copies of the stolen data (GovInfoSecurity). Only one listing has been confirmed by the victim itself: the UK's Police National Legal Database, which acknowledged the exposure of contact details for more than 100,000 police officers, staff and criminal justice professionals. The rest of the roster remains unverified, and at least one vendor analysis holds that parts of it are exaggerated or fabricated.
What Happened
ExfilSquad had no public track record before July 26. Rather than building one victim at a time, it published its entire victim list at once. RuntimeWire, citing RansomLook's monitoring feed, recorded the Microsoft listing at 16:37:08 UTC amid several ExfilSquad entries published seconds apart, which points to a coordinated site launch rather than 15 near-simultaneous intrusions. Counts of the launch batch vary slightly by source: GovInfoSecurity and IT-Connect both say 15 organizations, while CybelAngel describes "roughly 15" across five countries.
The named victims reported across sources include Wesco International, Microsoft, Allstate, Analog Devices, Bonava, Viavi Solutions, the cities of Atlanta and Houston, the University of Newcastle, District of Columbia Public Schools, Zenith Bank, Frontier Airlines, TaylorMade, the UK Police National Legal Database (PNLD) and the UK Department for Education. Victims were given until August 5 to make contact.
The one incident with independent, victim-side confirmation is PNLD. The intrusion was detected on Sunday, July 26, the same day the leak site went live. PNLD has notified the Information Commissioner's Office and is working with the National Crime Agency and outside cybersecurity specialists. Notably, PNLD is not the Police National Computer or the Police National Database, is not a crime-recording system, and does not hold confidential information on victims, witnesses or offenders.
The Analog Devices thread is messier and worth separating carefully. In an SEC filing, the chipmaker disclosed a breach it detected on June 23 in which attackers stole files, and said the incident is not expected to be material. In the same filing it added that "separately and unrelated, on July 26, 2026, the Company was made aware of public reports regarding a disparate cybersecurity matter and is currently assessing its validity, scope, and any potential impact." SecurityWeek reads that as a reference to ExfilSquad's claim of 570,000 stolen records, and notes that Analog Devices subsequently stopped appearing on the group's leak site. As a primary-tier filing, the company's own framing is that the June incident and the ExfilSquad claim are distinct matters, and neither has been publicly linked to the other.
The Microsoft listing is the weakest link in the chain and the loudest. ExfilSquad claimed 130 GB of uncompressed data and roughly 8 million records with an August 5 deadline. Both IT-Connect and RuntimeWire report that no screenshot, file listing or technical indicator accompanied the post, and that researchers found nothing establishing the files came from Microsoft systems. SOCRadar's analysis, cited by SecurityWeek, concluded that some of the group's claims appear exaggerated or fabricated, and raised the possibility that material is recycled from older or unrelated leaks.
What Was Taken
Confirmed by the victim, PNLD: full names, organizations and work email addresses belonging to police officers, police staff, criminal justice professionals, government partners and customers, plus names and email addresses of members of the public who submitted questions through the public-facing "Ask the Police" service. PNLD states there is no evidence that passwords or other security credentials were compromised.
Volume figures for PNLD differ depending on who is counting, and the distinction matters. BleepingComputer reports contact data for more than 100,000 officers and criminal justice professionals compromised; ExfilSquad itself claims 1.9 GB and approximately 135,000 records. As of August 3, PNLD had not published a victim total, a start date for the intrusion, a dwell time or a data volume. Blade Intel and Hacks.gr both flag that the widely repeated figure of 108,429 comes from PNLD's own 2025-26 annual summary and is a count of registered police users, not breach victims. Treat 108,429 as a ceiling on the user base, not a casualty count.
Attacker-claimed figures for the rest of the roster, none independently verified: 2.6 million records from Wesco International, 570,000 from Analog Devices, and 8 million records across 130 GB from Microsoft. The Microsoft listing described personal information, employee and customer contact details, authentication data and password hashes, portal identities and enterprise account information, facility management records, internal service tickets and access rights. Every one of those categories comes from the extortion listing itself and has not been authenticated by any outside party.
GovInfoSecurity reports one restraint worth noting: in the District of Columbia Public Schools case, the actors appear to have withheld some material rather than publishing everything, which the outlet frames as the group demonstrating a degree of self-imposed limits.
Why It Matters
The exfiltration-only model removes the loudest signal defenders rely on. There is no encryption event, no ransom note on a file server, no operational outage to trigger an incident response bridge. Analog Devices explicitly told the SEC its June incident did not disrupt operations. If your detection strategy is anchored on encryption behavior or availability loss, this class of actor completes its objective and you find out when your name appears on a leak site.
The second issue is verification asymmetry. ExfilSquad's launch shows how a new actor can borrow credibility by naming a household brand. The Microsoft claim generated headlines with zero technical substantiation behind it, and as RuntimeWire notes, a screenshot with plausible corporate field names can be assembled from public, previously leaked or unrelated data without ever touching the named target. Defenders and executives will face pressure to respond publicly to claims that may be hollow. Attaching a confidence level to each listing before responding is the discipline that matters here.
Third, the confirmed PNLD data is precision phishing fuel. Names, employers and work email addresses for police officers and criminal justice staff, mapped across all 43 Home Office forces and British Transport Police, are exactly what makes a lure targeting a named officer credible. UK government guidance cited by Blade Intel and Hacks.gr makes the same point. The same logic extends to any downstream supplier relationship visible in the leaked contact sets.
Finally, the shift from claims to torrents on August 7 changes the calculus. Once complete copies are seeded to a peer-to-peer network, takedown is not a realistic remedy. The group's own leak-site message leans on precisely that permanence: pay, or the data circulates indefinitely.
The Attack Technique
Accounts here are thin and should not be overstated. No source in this set identifies a confirmed intrusion vector for any ExfilSquad victim. The Microsoft leak page named no intrusion method, no affected system and no technical indicator that defenders could use to validate the claim.
CybelAngel's write-up asserts that on the evidence gathered so far, no exploit was written, no malware was used and no password was cracked, and points to a technical explanation from an independent research firm. That analysis is a single OTHER-tier source and the substance of the explanation is not reproduced in the material available here, so it should be treated as a lead rather than a finding.
One thread has been noted by multiple observers but remains circumstantial. Blade Intel and Hacks.gr both report that PNLD stated in its 2023-24 annual summary that the database uses Microsoft Power Platform technology. Neither PNLD nor any investigating body has attributed the breach to that platform, and no source in this set draws a causal link. It is a data point about the environment, not an established root cause.
What the pattern does support: a group that operates at the data layer rather than the endpoint layer, moves large volumes out without deploying encryption, and appears to have staged its victim disclosures for maximum simultaneous impact. Whether those 15 intrusions were genuinely independent operations or a repackaging of previously obtained data is, per SOCRadar, an open question.
What Organizations Should Do
- Check your own name and your suppliers' names against the leak site roster before reacting publicly. If you are listed, demand or seek proof of access such as file listings, unique internal identifiers, or records that could not have come from a prior public leak, before treating the claim as a confirmed breach or issuing a notification.
- Instrument for volumetric egress, not just encryption. Build detections on anomalous bulk reads and outbound transfer volume from databases, SaaS tenants and file stores, since an exfiltration-only actor never trips ransomware behavioral rules.
- Audit low-code and SaaS platform data stores specifically, including Power Platform, Dataverse and similar environments, for over-permissive sharing, orphaned connectors and service accounts with broad read scope. These are frequently outside the monitoring perimeter built around traditional servers.
- Push identity-directory and contact-database exports behind step-up controls. The PNLD case shows the damage a name-plus-organization-plus-work-email set does on its own, without a single credential being compromised.
- Warn named individuals directly. If staff appear in leaked contact data, tell them explicitly that they are now a targeted phishing population, and expect lures referencing their actual employer, role and colleagues.
- Pre-brief legal and communications on the unverified-claim scenario. Decide in advance who assesses evidentiary quality, what threshold triggers regulator notification, and what you say publicly when a claim is loud but unsubstantiated.
- Assume permanence once torrents appear. Shift response effort from containment of the file to reducing the value of the data, through credential rotation where relevant, heightened social-engineering verification, and monitoring for downstream fraud.
Sources: Exfiltration-Focused ExfilSquad Starts Leaking Stolen Data | ExfilSquad hackers leak info of over 100,000 UK police officers, staff | Semiconductor Firm Analog Devices Discloses Data Breach | ExfilSquad Claims Microsoft Breach, But Evidence Is Thin | PNLD Breach Exposes U.K. Police and Government Contact Details on D... | ExfilSquad claims Microsoft breach, but the evidence remains unveri... | Details of police and government collaborators… Hacks.gr | ExfilSquad: 7 Things Security Teams Need to Know