Get Your Free Report
Start for Free
SOCRadar® Cyber Intelligence Inc. | Dark Web Profile: ExfilSquad
Jul 28, 2026
8 Mins Read
Moon

Dark Web Profile: ExfilSquad

ExfilSquad is an emerging data-extortion group that surfaced with a rapid wave of public claims and a Tor-hosted Data Leak Site (DLS). The group is associated with an “only exfiltration” model, suggesting a focus on data theft rather than confirmed file encryption. Their listings remain highly questionable and may involve reused data or fabricated allegations, with fabrication currently appearing more likely based on the limited material available.

This Dark Web Profile reviews what is currently known about ExfilSquad, its operating model, and relevant defensive priorities.

Who Is ExfilSquad?

ExfilSquad is an emerging data-extortion group that appears to have surfaced publicly on July 26, 2026. It launched with an active Tor-based Data Leak Site (DLS), payment deadlines, and claims involving 15 organizations, including Microsoft.

ExfilSquad logo

ExfilSquad logo

No earlier activity has been reliably linked to the group. We have not identified any known aliases, predecessor operations, or rebranding history, leaving ExfilSquad’s current leak-site activity as the only verifiable picture of the operation.

Its visible model follows a familiar data-extortion pattern: naming organizations publicly, describing allegedly stolen information, and using the threat of disclosure to pressure them into paying. However, there is not enough evidence to classify ExfilSquad as a mature ransomware operation or Ransomware-as-a-Service (RaaS) enterprise. No confirmed affiliate program, recruitment campaign, revenue-sharing structure, or proprietary ransomware has surfaced.

Observed Operating Model

ExfilSquad’s visible model centers on public claims of data theft and extortion. The operation appears to use a dedicated DLS to name alleged victims and describe the categories or volume of information supposedly obtained, then relies on public exposure and pressure tactics.

Security teams should expect exposure signals around victim naming, sudden references to sensitive organizational data, and repetition of claims across monitoring pages. Teams should distinguish actor-controlled publication, third-party reporting, and confirmed victim statements.

Data Leak Site and Exposure Channel

According to our observations, the known exposure channel is a Tor-hosted DLS titled ExfilSquad, running on nginx. The site lists victim names, revenue figures, claimed data volumes, and summaries of allegedly stolen information, alongside a payment deadline and an email and TOX contact for negotiation.

This pattern is consistent with claim-based data extortion: the actor publishes a victim name and alleged data themes, then uses public exposure to create pressure.

Data leak site (DLS) of ExfilSquad

Data leak site (DLS) of ExfilSquad

Primary evidence does not yet connect ExfilSquad to a Ransomware-as-a-Service model. Early reporting has also questioned the credibility of some victim listings, suggesting they may be exaggerated or fabricated. Given the limited evidence and short observation period, these assessments should be treated cautiously.

What Are ExfilSquad’s Targets?

So far, government-linked organizations have been impacted more than any other sector, with technology companies representing the next-largest share of claims. Manufacturing, education, and financial services make up a smaller, roughly even middle tier, while transportation and retail account for the least. The sample remains too limited and too recent to establish a firm targeting pattern beyond an apparent preference for large, data-rich organizations.

Top industries targeted by ExfilSquad

Top industries targeted by ExfilSquad

Geographically, early claims point to the United States as by far the most heavily impacted country, well ahead of any other. The United Kingdom follows as a distant second, with Sweden and Nigeria each linked to a single claim so far. This distribution reflects claim classifications from the group’s leak site rather than confirmed incident locations, and could shift as the group’s activity develops.

Top countries targeted by ExfilSquad

Top countries targeted by ExfilSquad

The visible claims emphasize organizations with large, structured data repositories and sensitive public or commercial relationships. Alleged data themes include customer records, employee information, student and parent data, service requests, account information, and law-enforcement contacts. The sample is too new and unverified to establish consistent targeting logic.

Claims Linked to ExfilSquad

  • July 26, 2026: All 15 initial claims appear within a single day, spanning Wesco International, Analog Devices, Bonava, City of Atlanta, City of Houston, Viavi Solutions, Newcastle University, District of Columbia Public Schools, Zenith Bank Plc, Frontier Airlines, TaylorMade & Sun Day Red golf, Allstate, Microsoft, the Police National Legal Database, and the UK Department for Education. No forensic detail, data sample, or independent confirmation has accompanied any of these claims.

ExfilSquad has not provided forensic evidence, verifiable data samples, or independent confirmation for any of its claims. Their concentrated timing may indicate a coordinated site launch or bulk publication. Based on the limited evidence available, the listings may involve reused data or fabricated allegations, with fabrication currently appearing more likely.

  • July 27, 2026: ExfilSquad posted directly on X, tagging Microsoft’s security-intelligence account and sharing a screenshot resembling an internal Dynamics 365-style directory record for a senior executive account. Its authenticity remains unconfirmed, consistent with the rest of the group’s claims.

ExfilSquad's post on X, tagging Microsoft's security team with an alleged internal record

ExfilSquad’s post on X, tagging Microsoft’s security team with an alleged internal record

What Are ExfilSquad’s Techniques?

Initial Access and Reconnaissance

No ExfilSquad-specific initial-access method is confirmed. Reports mentioning remote-access services or vulnerability exploitation remain uncorroborated. Defenders should investigate those possibilities only as general hypotheses, not as actor-attributed TTPs.

Data Collection and Exfiltration

The “Only exfiltration” label and claimed record volumes indicate an apparent focus on stolen data. However, reviewed sources provide no validated tooling, staging artifacts, transfer mechanism, or evidence of cloud-storage use. Large claimed datasets make access logging, unusual archive creation, and outbound-volume monitoring important investigative areas.

Publication and Leak Workflow

The observed workflow involves a DLS that names alleged victims, states a payment deadline, and summarizes supposedly stolen records. The publication burst occurred around July 26, 2026, but the cadence may change as the operation develops. Defenders should observe internal data-movement anomalies and external claim activity while validating each claim against telemetry and victim communications.

What Are the Mitigation Tactics Against ExfilSquad?

ExfilSquad’s current model creates risk even without confirmed encryption. Public claims can expose personal, customer, employee, student, financial, or law-enforcement-related information and may trigger regulatory, contractual, and notification obligations, alongside credential-reuse risk, brand impersonation, targeted social engineering, and pressure on incident-response teams. These risks are most relevant to organizations whose data appears in the claim set or whose telemetry shows unusual access and outbound movement; teams should prioritize validation rather than assume every published claim represents a confirmed breach.

Validate and Prioritize

  • Validate DLS claims against identity-provider, VPN, endpoint, database, cloud, and DLP telemetry.
  • Prioritize sensitive repositories containing PII, student records, customer data, employee information, and public-service records.

Harden Access and Monitor Activity

  • Audit remote-access exposure and enforce MFA for VPN, administrative, and other externally reachable services.
  • Monitor privileged-account activity for unusual access, service changes, scheduled tasks, or large-volume queries.
  • Review abnormal outbound traffic and unexpected archive creation from systems holding high-value data.

Protect Backups

  • Protect backup and recovery paths with offline, encrypted, and regularly tested backups.

Prepare Communications and Track Indicators

  • Prepare breach communications for claims involving public-sector, education, financial, or law-enforcement data.
  • Track the listed contact indicators in threat-intelligence workflows without relying on the Tor service as a permanent indicator.

Evidence gap: no confirmed ExfilSquad intrusion path or toolset is available, so these controls address the observed exfiltration and publication model rather than a validated attack chain. Teams should treat ExfilSquad as a low-confidence but active data-extortion operation and watch for new victim claims, changes to the DLS, corroborated victim disclosures, and any sign that the operation expands beyond its reported exfiltration-focused model.

What Are the MITRE ATT&CK TTPs of ExfilSquad?

MITRE mapping not provided due to insufficient ExfilSquad-specific evidence in the available sources. General techniques related to web-service exfiltration, data staging, or encryption should not be attributed to the operation without validated procedure examples.

What Are the Indicators of Compromise (IOCs) for ExfilSquad?

No confirmed technical IOCs are publicly available for ExfilSquad.

We have not identified malware hashes, ransomware filenames, encrypted extensions, ransom-note names, command-and-control addresses, attack IPs, cryptocurrency wallets, or validated domains associated with an intrusion.

Actor Contact Indicators

  • Email: exfilsquad[at]onionmail[.]org
  • TOX ID: 8F4BCBC804C3DB35112D0FCC0E8E02F48BD1F041E8395658A8E9D3E3D2A98C221362B3C3C93F

These values are actor contact identifiers, not compromise indicators. Their presence in intelligence reporting or communications may support an investigation, but they do not prove that a system or organization has been breached.

Research into ExfilSquad remains ongoing. This profile will be updated as its claims are verified, disproven, or supported by new technical evidence.