Full Report
What HappenedIn mid-2026, an emerging cybercriminal group known as ExfilSquad launched a high-profile extortion campaign targeting prominent UK organisations across the public sector, education, and law enforcement, as well as other firms worldwide.Unlike traditional ransomware groups, ExfilSquad does not deploy encryptors or destructive malware. Instead, they operate as a pure data extortion group, stealing data and threatening to publish it on their onion-based Data Leak Site (DLS) if a ransom is not paid.Several prominent UK entities have confirmed breaches linked to the group:UK Department for Education (DfE): Approximately 600,000 records stolen from its Help Portal containing parent and staff contact details (names, emails, phone numbers, job titles), plus around 7,000 records from the Turing Portal.Police National Legal Database (PNLD): Stole 1.9 GB of data (around 135,000 records) containing contact information for over 100,000 serving police officers, staff, and criminal justice professionals, alongside around 21,000 "Ask the Police" public inquiry records.Newcastle University: Approximately 440,000 records compromised containing applicant and student contact information, personally identifiable information (PII), and admissions database records caused by a technical configuration flaw connecting to an admissions system.Analysis of the details left on the data leak site revealed that ExfilSquad's primary attack vector involves exploiting misconfigurations in cloud portals, customer relationship management (CRM) platforms, internal case management systems, as well as Microsoft Power Pages data tables left publicly accessible without proper authentication.To force compliance and prove their claims are real, ExfilSquad uploaded multi-gigabyte torrent files for each victim to their TOR leak site. Resecurity noted that ExfilSquad assigns a distinct Torrent Tracker and initial Web Seed per victim.Analyst CommentWhile ExfilSquad is a new group, they appear to be already experienced at running these types of attacks, suggesting they have a history of cybercrime. Plus, ExfilSquad’s recent campaign highlights the growing trend of transitioning from file-encrypting ransomware to extortion driven entirely by cloud and SaaS misconfigurations. Organisations that have invested in defending against endpoint-based threats are often leaving critical business application interfaces exposed.SaaS platforms continue to be primary targets of English-speaking cybercrime communities. In recent years, customers of major SaaS providers, such as Salesloft, Salesforce, and Snowflake have all been extorted. Microsoft Power Pages portals, CRM databases, and customer support helpdesks frequently hold vast repositories of sensitive contact data and interaction histories. When internet-facing API endpoints or data table permissions are left unauthenticated or unpatched, cybercriminals can systematically scrape massive volumes of data without ever needing to drop a payload or escalate privileges internally.ExfilSquad’s reliance on torrent distribution further amplifies reputational and operational damage. While gangs like LockBit, Clop, and Akira have previously utilised torrents, ExfilSquad’s operational twist of assigning unique Torrent Trackers and dedicated Web Seeds to individual victims ensures that leaked files distribute rapidly across P2P networks, making it extremely difficult to perform a takedown.While ExfilSquad’s breaches have largely compromised contact directories and administrative support records, the real-world risks remain significant. Exposing work emails, names, and organisational structures for over 100,000 police officers and civil servants poses distinct social engineering, spear-phishing, and physical security concerns that impacted institutions will have to manage long after the breach occurs.Defensive TakeawaysAudit Microsoft Power Pages and Public SaaS Tables: Regularly review public data table permissions, web API settings, and unauthenticated browser views across Microsoft Power Pages, CRMs, and customer support portals to ensure backend data tables are not exposed to the public internet.Harden CRM and Case Management Integrations: Treat external-facing admissions portals, helpdesks, and case management systems as high-risk platforms. Implement strict access controls, conduct routine configuration audits, and enforce proper API token security.Deploy External Attack Surface Management (EASM): Utilise continuous external attack surface scanning to detect newly exposed web endpoints, misconfigured database connectors, and publicly exposed storage buckets before malicious actors locate them.Incorporate Pure Extortion into Incident Response Plans: Security teams must adapt incident response playbooks for data-theft-only scenarios. Organisations may seek to establish protocols for monitoring peer-to-peer (P2P) networks and managing public disclosures when stolen data is distributed via torrents.Relevant Sourceshttps://www.computing.co.uk/news/2026/security/newcastle-university-data-breach-exfilsquadhttps://www.thetimes.com/uk/crime/article/who-are-exfilsquad-hackers-cyberattacks-dtzhvvzgjhttps://www.ncl.ac.uk/press/articles/latest/2026/07/statementonpotentialunauthoriseddataaccess/https://www.bbc.co.uk/news/articles/cq6dmgrp21pohttps://www.pnld.co.uk/article/?id=7ebf3c0e-598e-f111-8077-7ced8d3aa78fRelevant CTI Sourceshttps://www.ransomware.live/group/ExfilSquadhttps://www.resecurity.com/blog/article/exfilsquad-targets-new-victims-shares-data-via-torrentshttps://socradar.io/blog/dark-web-profile-exfilsquad/https://www.sans.org/blog/hunting-saas-threats-insights-for589-course-cybercriminal-campaigns
Analysis Summary
# Threat Actor: ExfilSquad
## Attribution & Identity
* **Name/Alias:** ExfilSquad
* **Actor Identification:** An emerging cybercriminal group characterized as a "pure data extortion" group.
* **Known Associations:** While a new entity (emerged mid-2026), analysts suggest the members are experienced and likely have a history in cybercrime due to the sophistication of their campaigns. They are noted as part of the English-speaking cybercrime community.
## Activity Summary
In mid-2026, ExfilSquad launched a high-profile extortion campaign targeting UK-based public sector, education, and law enforcement organizations. Unlike traditional ransomware groups, they eschew encryption (ransomware) in favor of stealing massive volumes of data and threatening public disclosure on their dedicated leak site to force ransom payments.
## Tactics, Techniques & Procedures
* **Pure Data Extortion:** Does not use destructive malware or encryptors; focuses solely on data exfiltration and ransom threats.
* **Exploitation of Misconfigurations:** Targets publicly accessible cloud portals and SaaS platforms.
* **Data Scraping:** Systematically scrapes data from internet-facing API endpoints and data tables that lack proper authentication.
* **P2P Distribution:** Utilizes BitTorrent protocols for data leaks to ensure rapid distribution and make takedowns difficult.
* **Unique Tracking:** Assigns a distinct Torrent Tracker and dedicated initial Web Seed per victim to amplify pressure.
* **MITRE ATT&CK IDs:**
* **T1530:** Data from Cloud Storage
* **T1567:** Exfiltration Over Web Service
* **T1584.005:** Cloud Resources (Exploiting misconfigured SaaS)
* **T1190:** Exploit Public-Facing Application
## Targeting
* **Sectors:** Education, Law Enforcement, Public Sector, and general commercial firms.
* **Geography:** Primary focus on the United Kingdom, with additional targets worldwide.
* **Victims:**
* **UK Department for Education (DfE):** 607,000 records stolen via Help and Turing Portals.
* **Police National Legal Database (PNLD):** 1.9 GB of data involving 100,000+ police officers and staff.
* **Newcastle University:** 440,000 records compromised via admissions system flaw.
## Tools & Infrastructure
* **Malware:** None reported (payloadless attacks).
* **Infrastructure:**
* **Data Leak Site (DLS):** Onion-based TOR site.
* **Distribution:** BitTorrent P2P networks.
* **Seeds/Trackers:** Unique Torrent Trackers and Web Seeds per victim.
* **Targeted Platforms:** Microsoft Power Pages, Salesforce, Salesloft, Snowflake, and various CRM/Helpdesk platforms.
## Implications
ExfilSquad’s activities represent a strategic shift from endpoint-focused ransomware to SaaS-focused extortion. The exposure of over 100,000 police officers' contact details and organizational structures creates long-term risks for social engineering, targeted spear-phishing, and potential physical security threats. The use of torrents for data leaks ensures that once data is stolen, it remains highly accessible on the internet, compounding reputational damage.
## Mitigations
* **Audit Microsoft Power Pages & SaaS:** Regularly review permissions for public data tables and web API settings to ensure backend data is not unauthenticated.
* **Harden CRM & Case Management:** Implement strict access controls and API token security for helpdesks and admissions portals.
* **External Attack Surface Management (EASM):** Deploy continuous scanning to detect newly exposed endpoints, storage buckets, or database connectors.
* **Incident Response Adaptation:** Update IR playbooks to include specific protocols for pure extortion scenarios and P2P network monitoring for leaked data.
* **Source Defanging:**
* hxxps[://]www[.]ransomware[.]live/group/ExfilSquad
* hxxps[://]www[.]resecurity[.]com/blog/article/exfilsquad-targets-new-victims-shares-data-via-torrents
* hxxps[://]socradar[.]io/blog/dark-web-profile-exfilsquad/