logo

ExfilSquad Targets New Victims, Shares Data via Torrents

ID: 191e3586-f033-5b3d-a5ce-bd7fabd677e8

STIX ID: report--191e3586-f033-5b3d-a5ce-bd7fabd677e8

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2026-08-11

Date Updated: 2026-08-11

Author: Pierluigi Paganini

...
...

ExfilSquad, an emerging cybercrime collective, announced 13 victims across the U.S., UK and Sweden and is leveraging misconfigured cloud/SaaS portals (Microsoft Dataverse, Power Pages, CRMs) to exfiltrate large datasets; instead of encrypting systems, they publish stolen data via unique torrent trackers and web seeds to maximize spread and damage, with Resecurity noting active seeders from hosts in China and Russia and referencing a prior compromise of the UK Police National Legal Database affecting over 100,000 records.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.