SYS::ONLINE
Wasteland.
Briefs2197
Issues24
SinceFeb 2026
LIVE
▣ Breach EXFILSQUAD-MULTI-V 2026-08-16

13 Organizations: ExfilSquad Mass Data Extortion Campaign Confirmed

"Fortra Intelligence and Research Experts (FIRE) have reviewed the data samples published by the ExfilSquad data extortion group and concluded that the crew's core claim is genuine: it holds sensitive data from at least…"

Fortra Intelligence and Research Experts (FIRE) have reviewed the data samples published by the ExfilSquad data extortion group and concluded that the crew's core claim is genuine: it holds sensitive data from at least 13 victim organizations spanning government, education, financial services and manufacturing, according to Infosecurity Magazine and SC Media. The archive published on 7 August 2026 totalled 382.64 GB and roughly 27 million records across those 13 victims. Named organizations include the City of Atlanta, the UK Department for Education (DfE), the UK Police National Legal Database (PNLD) and District of Columbia Public Schools (DCPS). At least three victims have now confirmed incidents publicly in their own words: PNLD, the DfE and Wesco International.

What Happened

ExfilSquad surfaced on 26 July 2026 and immediately listed 15 alleged victims on an onion-based leak site. DarkOwl, which crawled the site on 6 August, reports the claimed victim set breaks down as nine US, three UK, one Swedish and one Nigerian organization, and notes that every listing carried an identical ransom deadline of 5 August 2026. DarkOwl reads that uniform deadline as evidence of a single coordinated extortion wave rather than 15 independent intrusions. That is a single OTHER-tier assessment and should be treated as a working hypothesis, not established fact, though the FIRE finding of a common initial access pattern is consistent with it.

When the deadline passed, ExfilSquad published torrent dumps for 13 of the 15 on 7 August, claiming those organizations "did not meet the agreements." Two names from the original list, Zenith Bank Plc and Analog Devices, were absent from the dumps, the FIRE team noted. Worth flagging: BleepingComputer's 11 August report describes ExfilSquad as "known for data breaches at Analog Devices," so reporting is not aligned on whether the Analog Devices claim was ever substantiated. On the FIRE evidence, no Analog Devices data was published.

The 26 July date does double duty. It is both the day the leak site appeared and the day PNLD says it identified its own data security incident, per the victim's 3 August statement.

What Was Taken

The picture varies sharply by victim, and the numbers depend heavily on who is talking.

PNLD (operated by West Yorkshire Police). In its own statement, PNLD confirmed that names, organizations and work email addresses of police officers, police staff, criminal justice professionals, government partners and customers were compromised and published on the dark web. A second service, the public-facing Ask the Police enquiry site, was also affected: names and email addresses of citizens who had previously submitted questions were published. PNLD stated there is no evidence passwords or other security credentials were compromised, and stressed that it holds no confidential material on victims, witnesses or offenders, and is not the Police National Computer or the Police National Database. On volume, accounts differ. BleepingComputer reported that contact data of more than 100,000 police officers and other criminal justice professionals was compromised; ExfilSquad itself claims 1.9 GB and approximately 135,000 contact records including police force areas. The Register noted that PNLD has not published its own affected-person count, and ctipilot.ch records that the 135,000 figure originated in third-party reporting rather than the victim. Treat 135,000 as an actor claim.

Department for Education. Computer Weekly, citing The Times, put the theft at more than 600,000 records including full names, email addresses and phone numbers of government and university staff and senior school officials such as headteachers. The Register cites the ExfilSquad listing as claiming around 600,000 parent and staff contact records plus a further 7,000 from the Turing Portal, and reports the department confirmed a figure above 607,000. So the range runs from "more than 600,000" (The Times via Computer Weekly) to "more than 607,000" as confirmed by the department itself, with the actor's own listing splitting the total across two portals.

DCPS. Roughly 60,000 records containing student names, dates of birth, unique student identifiers and other PII were leaked. ExfilSquad attached a note claiming it released only a censored version and had "shredded the original entirely from our servers" because it would not dox schoolchildren, while still asserting it wanted to expose DCPS handling of data on children as young as six. There is no independent verification that any original copy was destroyed. Assume it was not.

Wesco International. ExfilSquad claims 2.6 million records covering customer and employee PII, account and contact data, CRM user profiles, and credit and business identifiers. Wesco's own position, given to BleepingComputer by VP of Corporate Communications Jennifer Sniderman, is materially different: the company confirmed it is investigating an incident in its cloud CRM environment, said it worked with its cloud CRM vendor, and stated it does not believe payment card information, financial account information or other sensitive customer or employee data is at risk. Wesco reported no business disruption and no evidence of ransomware or other malicious software on its IT systems. This is a direct conflict between actor claim and victim statement, and it is unresolved.

Where Accounts Differ

Two disagreements are worth naming plainly rather than smoothing over.

First, the initial access vector for the DfE. FIRE's leading theory for the campaign as a whole is misconfigured Microsoft Power Pages portals. Computer Weekly, however, reported that the DfE breach involved a social engineering attack against an internal helpdesk used by school and university staff and local authorities. Those are not the same attack. It is possible both are true across a multi-victim campaign, but on the DfE specifically the published accounts conflict.

Second, root cause attribution generally. ctipilot.ch is explicit that researchers traced the broader ExfilSquad campaign to anonymously readable Power Pages portals but did not establish that as PNLD's own root cause, and The Register confirms PNLD has not said how the attackers got in. Do not treat the Power Pages theory as a confirmed finding for every victim on the list.

Also unresolved: ExfilSquad's claimed breach of Microsoft, which Computer Weekly characterises as alleged and unconfirmed. An early ctipilot.ch assessment went further, judging that most of the group's non-DfE claims looked fabricated, an assessment that the FIRE analysis has since substantially overturned for 13 of the 15.

Why It Matters

This campaign is a clean illustration of a threat model most organizations still underweight. There is no ransomware, no encryption, no lateral movement worth the name, and in Wesco's case no evidence of malware on internal IT at all. The damage is done entirely through data that a SaaS platform was configured to hand out.

The victim mix matters too. Contact directories are treated as low-sensitivity data almost everywhere, yet a validated list of 100,000-plus UK police officers and criminal justice professionals with names, employers, work email addresses and force areas is a high-grade targeting package for phishing, pretexting and, in the worst case, physical targeting. As ESET's Jake Moore put it in comments on the DfE breach, criminals can do a lot by piecing together a data jigsaw and building convincing follow-up phishing. That applies with more force when the jigsaw pieces are law enforcement staff.

For regulated entities, the sequence here also compresses the response window brutally: claim, deadline, mass torrent publication, all inside roughly 12 days. There was no long negotiation phase in which to prepare notifications.

The Attack Technique

FIRE assesses that the breaches are most likely limited to unauthorized access of Microsoft Dynamics 365 CRM and ERP instances, with the leading theory on initial access being misconfigured Microsoft Power Pages portals that permitted public read access.

The specific misconfiguration is a known and documented failure mode rather than a vulnerability: when the Anonymous Users web role is assigned to a table permission in Power Pages, any unauthenticated visitor to the site inherits read access to the underlying Dataverse table. There is no exploit involved. The data is served to whoever asks. FIRE's assessment is that ExfilSquad most likely built its victim list by crawling the internet for exposed portals in this state, which fits both the sector spread and the simultaneous deadline DarkOwl observed.

Wesco's confirmation that its incident sits in the cloud CRM environment, and that it engaged its cloud CRM vendor, is consistent with this theory, though the company has not named the platform.

What Organizations Should Do

  1. Audit every Power Pages site for anonymous table permissions now. In the Power Pages management app, enumerate all table permissions and identify any bound to the Anonymous Users web role. Confirm each one is deliberate, and confirm exactly which Dataverse columns it exposes, not just which table.
  2. Treat portal exposure as an internet-facing asset class. Public-facing low-code portals frequently sit outside both the vulnerability management program and the CMDB. Enumerate every Power Pages, Power Apps portal and equivalent low-code front end your tenant has published, including ones spun up by business units.
  3. Review Dataverse column-level security on contact and account tables. Where anonymous read is genuinely required, restrict it to the minimum column set. Full contact records with dates of birth or unique identifiers, as in the DCPS case, should never be reachable by an unauthenticated role.
  4. Instrument for bulk read, not just intrusion. This campaign generates no malware and no privilege escalation. The only detectable signal is anomalous volume and velocity of legitimate reads from anonymous sessions. Set thresholds and alerting on portal request rates and Dataverse query volumes.
  5. Harden the helpdesk against social engineering. Given the DfE account of a helpdesk-based social engineering vector, enforce out-of-band identity verification for any support request involving account access, credential reset or data export, and log those verifications.
  6. Prepare for contact-data breach notification specifically. Have a pre-drafted regulator notification path (ICO or equivalent) and an affected-organization contact process ready. PNLD contacted all affected organizations within days and notified the ICO, which is the standard to plan against given how little time the deadline structure allows.
  7. Warn staff whose contact details were exposed. Anyone in the DfE, PNLD or Ask the Police datasets should be briefed to expect targeted phishing referencing their real role and employer, and told that unsolicited contact citing accurate internal details is now an expected consequence, not a sign of a further breach.

Sources: Researchers Confirm ExfilSquad’s Access to Sensitive Data - Infosec... | ExfilSquad hackers leak info of over 100,000 UK police officers, staff | Police National Legal Database confirms data theft after dark web leak | Wesco confirms security incident after ExfilSquad claims data theft | ExfilSquad data extortion group linked to 13 victim data leaks bri... | Department for Education suffers data breach Computer Weekly | ExfilSquad: A New "Data extortion group” DarkOwl | PNLD confirms the police contact-data breach and names a second aff...