Visualização normal

Antes de ontemStream principal
  • ✇@BushidoToken Threat Intel
  • UK Cybercrime Journal: ExfilSquad Emerges BushidoToken
    What HappenedIn mid-2026, an emerging cybercriminal group known as ExfilSquad launched a high-profile extortion campaign targeting prominent UK organisations across the public sector, education, and law enforcement, as well as other firms worldwide.Unlike traditional ransomware groups, ExfilSquad does not deploy encryptors or destructive malware. Instead, they operate as a pure data extortion group, stealing data and threatening to publish it on their onion-based Data Leak Site (DLS) if a ransom
     

UK Cybercrime Journal: ExfilSquad Emerges

2 de Setembro de 2026, 06:00

What Happened

  • In mid-2026, an emerging cybercriminal group known as ExfilSquad launched a high-profile extortion campaign targeting prominent UK organisations across the public sector, education, and law enforcement, as well as other firms worldwide.
  • Unlike traditional ransomware groups, ExfilSquad does not deploy encryptors or destructive malware. Instead, they operate as a pure data extortion group, stealing data and threatening to publish it on their onion-based Data Leak Site (DLS) if a ransom is not paid.
  • Several prominent UK entities have confirmed breaches linked to the group:
    • UK Department for Education (DfE): Approximately 600,000 records stolen from its Help Portal containing parent and staff contact details (names, emails, phone numbers, job titles), plus around 7,000 records from the Turing Portal.
    • Police National Legal Database (PNLD): Stole 1.9 GB of data (around 135,000 records) containing contact information for over 100,000 serving police officers, staff, and criminal justice professionals, alongside around 21,000 "Ask the Police" public inquiry records.
    • Newcastle University: Approximately 440,000 records compromised containing applicant and student contact information, personally identifiable information (PII), and admissions database records caused by a technical configuration flaw connecting to an admissions system.
  • Analysis of the details left on the data leak site revealed that ExfilSquad's primary attack vector involves exploiting misconfigurations in cloud portals, customer relationship management (CRM) platforms, internal case management systems, as well as Microsoft Power Pages data tables left publicly accessible without proper authentication.
  • To force compliance and prove their claims are real, ExfilSquad uploaded multi-gigabyte torrent files for each victim to their TOR leak site. Resecurity noted that ExfilSquad assigns a distinct Torrent Tracker and initial Web Seed per victim.

Analyst Comment

While ExfilSquad is a new group, they appear to be already experienced at running these types of attacks, suggesting they have a history of cybercrime. Plus, ExfilSquad’s recent campaign highlights the growing trend of transitioning from file-encrypting ransomware to extortion driven entirely by cloud and SaaS misconfigurations. Organisations that have invested in defending against endpoint-based threats are often leaving critical business application interfaces exposed.

SaaS platforms continue to be primary targets of English-speaking cybercrime communities. In recent years,  customers of major SaaS providers, such as Salesloft, Salesforce, and Snowflake have all been extorted. Microsoft Power Pages portals, CRM databases, and customer support helpdesks frequently hold vast repositories of sensitive contact data and interaction histories. When internet-facing API endpoints or data table permissions are left unauthenticated or unpatched, cybercriminals can systematically scrape massive volumes of data without ever needing to drop a payload or escalate privileges internally.

ExfilSquad’s reliance on torrent distribution further amplifies reputational and operational damage. While gangs like LockBit, Clop, and Akira have previously utilised torrents, ExfilSquad’s operational twist of assigning unique Torrent Trackers and dedicated Web Seeds to individual victims ensures that leaked files distribute rapidly across P2P networks, making it extremely difficult to perform a takedown.

While ExfilSquad’s breaches have largely compromised contact directories and administrative support records, the real-world risks remain significant. Exposing work emails, names, and organisational structures for over 100,000 police officers and civil servants poses distinct social engineering, spear-phishing, and physical security concerns that impacted institutions will have to manage long after the breach occurs.

Defensive Takeaways

  • Audit Microsoft Power Pages and Public SaaS Tables: Regularly review public data table permissions, web API settings, and unauthenticated browser views across Microsoft Power Pages, CRMs, and customer support portals to ensure backend data tables are not exposed to the public internet.
  • Harden CRM and Case Management Integrations: Treat external-facing admissions portals, helpdesks, and case management systems as high-risk platforms. Implement strict access controls, conduct routine configuration audits, and enforce proper API token security.
  • Deploy External Attack Surface Management (EASM): Utilise continuous external attack surface scanning to detect newly exposed web endpoints, misconfigured database connectors, and publicly exposed storage buckets before malicious actors locate them.
  • Incorporate Pure Extortion into Incident Response Plans: Security teams must adapt incident response playbooks for data-theft-only scenarios. Organisations may seek to establish protocols for monitoring peer-to-peer (P2P) networks and managing public disclosures when stolen data is distributed via torrents.

Relevant Sources

  1. https://www.computing.co.uk/news/2026/security/newcastle-university-data-breach-exfilsquad
  2. https://www.thetimes.com/uk/crime/article/who-are-exfilsquad-hackers-cyberattacks-dtzhvvzgj
  3. https://www.ncl.ac.uk/press/articles/latest/2026/07/statementonpotentialunauthoriseddataaccess/
  4. https://www.bbc.co.uk/news/articles/cq6dmgrp21po
  5. https://www.pnld.co.uk/article/?id=7ebf3c0e-598e-f111-8077-7ced8d3aa78f

Relevant CTI Sources

  1. https://www.ransomware.live/group/ExfilSquad
  2. https://www.resecurity.com/blog/article/exfilsquad-targets-new-victims-shares-data-via-torrents
  3. https://socradar.io/blog/dark-web-profile-exfilsquad/
  4. https://www.sans.org/blog/hunting-saas-threats-insights-for589-course-cybercriminal-campaigns

  • ✇Security Affairs
  • PNLD Confirms Data Breach Affecting UK Police and Justice Staff Pierluigi Paganini
    UK police legal database breach exposed officers’ names and work emails, increasing phishing risks. NCA is investigating. The Police National Legal Database (PNLD), the legal reference system used by all 43 Home Office police forces in England and Wales, confirmed that a data breach exposed the contact details of police officers, staff, and criminal justice professionals and published them on the dark web. The breach also hit Ask the Police, a public Q&A service hosted on the same platfo
     

PNLD Confirms Data Breach Affecting UK Police and Justice Staff

3 de Agosto de 2026, 09:23

UK police legal database breach exposed officers’ names and work emails, increasing phishing risks. NCA is investigating.

The Police National Legal Database (PNLD), the legal reference system used by all 43 Home Office police forces in England and Wales, confirmed that a data breach exposed the contact details of police officers, staff, and criminal justice professionals and published them on the dark web. The breach also hit Ask the Police, a public Q&A service hosted on the same platform. The National Crime Agency is involved in the investigation.

“Information including the names, organisations and work email addresses of police officers, staff and other criminal justice professionals, government partners and customers has been compromised and published on the dark web.” reads the notice of data breach. “There is no evidence to suggest that passwords or other security credentials have been compromised.”

UK police is investigating the security breach with the help of the National Crime Agency (NCA) and private cybersecurity firms.

The PNLD reported 108,429 police registrations in its 2025-26 annual summary, which gives some sense of the potential user base affected, though PNLD has not disclosed how many individuals are actually in the breached dataset. No victim count, no timeline of when the intrusion began, no statement on how much data was taken.

“The data security incident primarily affected the Police National Legal Database (PNLD) which hosts the Ask the Police site.” continues the notice. “As a result, some names and email addresses of people who have previously submitted a question to Ask the Police have been published on the dark web.”

Ask the Police is a public-facing service where anyone can submit questions to the police. The exposure of those submitters’ names and emails alongside police officers’ work contact details creates two distinct risk categories: named officers are now more vulnerable to targeted phishing, and members of the public who contacted police services have had that fact made visible on criminal forums.

“PNLD also provides legal information, products and services to UK police forces and criminal justice organisations; it is not a crime recording system and does not hold confidential information relating to victims, witnesses, or offenders.” concludes the notice.

All affected organizations were promptly notified, provided guidance, and the incident was reported to the UK Information Commissioner’s Office (ICO).

The extortion group ExfilSquad listed PNLD on its leak site on July 26, though PNLD has not attributed the incident to the group.

Cybersecurity firm VenariX reviewed samples associated with 11 of ExfilSquad’s 15 claimed victims and found structures consistent with Microsoft Dataverse across all of them, pointing toward a likely campaign pattern involving misconfigured Microsoft Power Pages portals, public-facing sites where overly permissive table access settings can expose data to anyone who visits the page without logging in.

PNLD’s 2023-24 annual summary stated the database uses Microsoft Power Platform technology, and the breach notice page references assets on Microsoft’s content.powerapps.com domain, which corroborates the platform connection. That said, neither PNLD’s notice nor VenariX’s report has confirmed a PNLD-specific endpoint, permission setting, or access route, the Power Pages hypothesis remains exactly that: a hypothesis consistent with the evidence, not a confirmed root cause.

“The reviewed data is most consistent with extraction from public Microsoft Power Pages portals that were configured to allow anonymous users to read Dataverse records.” states VenariX. “Microsoft documents that Power Pages can expose Dataverse tables through its portal Web API using the /_api/<EntitySetName> route, and that access is governed by table permissions assigned through web roles.

A likely flow is:

Public Power Pages portal → Anonymous Users web role → Broad table permission → Power Pages Web API or legacy OData feed → Dataverse data export

For any organization running Microsoft Power Pages: VenariX recommends reviewing Anonymous Users table permissions, Web API settings, and legacy OData feeds, then validating access from an unauthenticated browser session. Microsoft provides a tenant-level control that blocks unauthenticated users from reading Dataverse data while still allowing public form submissions. That’s the kind of configuration that should have been validated before deployment, not after a breach.

Police officers and staff whose details were exposed should be alert to targeted phishing that uses their name, organization, and work email, the exact combination now available on the dark web.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, UK Police)

❌
❌