Visualização de leitura

UK Cybercrime Journal: ExfilSquad Emerges

What Happened

  • In mid-2026, an emerging cybercriminal group known as ExfilSquad launched a high-profile extortion campaign targeting prominent UK organisations across the public sector, education, and law enforcement, as well as other firms worldwide.
  • Unlike traditional ransomware groups, ExfilSquad does not deploy encryptors or destructive malware. Instead, they operate as a pure data extortion group, stealing data and threatening to publish it on their onion-based Data Leak Site (DLS) if a ransom is not paid.
  • Several prominent UK entities have confirmed breaches linked to the group:
    • UK Department for Education (DfE): Approximately 600,000 records stolen from its Help Portal containing parent and staff contact details (names, emails, phone numbers, job titles), plus around 7,000 records from the Turing Portal.
    • Police National Legal Database (PNLD): Stole 1.9 GB of data (around 135,000 records) containing contact information for over 100,000 serving police officers, staff, and criminal justice professionals, alongside around 21,000 "Ask the Police" public inquiry records.
    • Newcastle University: Approximately 440,000 records compromised containing applicant and student contact information, personally identifiable information (PII), and admissions database records caused by a technical configuration flaw connecting to an admissions system.
  • Analysis of the details left on the data leak site revealed that ExfilSquad's primary attack vector involves exploiting misconfigurations in cloud portals, customer relationship management (CRM) platforms, internal case management systems, as well as Microsoft Power Pages data tables left publicly accessible without proper authentication.
  • To force compliance and prove their claims are real, ExfilSquad uploaded multi-gigabyte torrent files for each victim to their TOR leak site. Resecurity noted that ExfilSquad assigns a distinct Torrent Tracker and initial Web Seed per victim.

Analyst Comment

While ExfilSquad is a new group, they appear to be already experienced at running these types of attacks, suggesting they have a history of cybercrime. Plus, ExfilSquad’s recent campaign highlights the growing trend of transitioning from file-encrypting ransomware to extortion driven entirely by cloud and SaaS misconfigurations. Organisations that have invested in defending against endpoint-based threats are often leaving critical business application interfaces exposed.

SaaS platforms continue to be primary targets of English-speaking cybercrime communities. In recent years,  customers of major SaaS providers, such as Salesloft, Salesforce, and Snowflake have all been extorted. Microsoft Power Pages portals, CRM databases, and customer support helpdesks frequently hold vast repositories of sensitive contact data and interaction histories. When internet-facing API endpoints or data table permissions are left unauthenticated or unpatched, cybercriminals can systematically scrape massive volumes of data without ever needing to drop a payload or escalate privileges internally.

ExfilSquad’s reliance on torrent distribution further amplifies reputational and operational damage. While gangs like LockBit, Clop, and Akira have previously utilised torrents, ExfilSquad’s operational twist of assigning unique Torrent Trackers and dedicated Web Seeds to individual victims ensures that leaked files distribute rapidly across P2P networks, making it extremely difficult to perform a takedown.

While ExfilSquad’s breaches have largely compromised contact directories and administrative support records, the real-world risks remain significant. Exposing work emails, names, and organisational structures for over 100,000 police officers and civil servants poses distinct social engineering, spear-phishing, and physical security concerns that impacted institutions will have to manage long after the breach occurs.

Defensive Takeaways

  • Audit Microsoft Power Pages and Public SaaS Tables: Regularly review public data table permissions, web API settings, and unauthenticated browser views across Microsoft Power Pages, CRMs, and customer support portals to ensure backend data tables are not exposed to the public internet.
  • Harden CRM and Case Management Integrations: Treat external-facing admissions portals, helpdesks, and case management systems as high-risk platforms. Implement strict access controls, conduct routine configuration audits, and enforce proper API token security.
  • Deploy External Attack Surface Management (EASM): Utilise continuous external attack surface scanning to detect newly exposed web endpoints, misconfigured database connectors, and publicly exposed storage buckets before malicious actors locate them.
  • Incorporate Pure Extortion into Incident Response Plans: Security teams must adapt incident response playbooks for data-theft-only scenarios. Organisations may seek to establish protocols for monitoring peer-to-peer (P2P) networks and managing public disclosures when stolen data is distributed via torrents.

Relevant Sources

  1. https://www.computing.co.uk/news/2026/security/newcastle-university-data-breach-exfilsquad
  2. https://www.thetimes.com/uk/crime/article/who-are-exfilsquad-hackers-cyberattacks-dtzhvvzgj
  3. https://www.ncl.ac.uk/press/articles/latest/2026/07/statementonpotentialunauthoriseddataaccess/
  4. https://www.bbc.co.uk/news/articles/cq6dmgrp21po
  5. https://www.pnld.co.uk/article/?id=7ebf3c0e-598e-f111-8077-7ced8d3aa78f

Relevant CTI Sources

  1. https://www.ransomware.live/group/ExfilSquad
  2. https://www.resecurity.com/blog/article/exfilsquad-targets-new-victims-shares-data-via-torrents
  3. https://socradar.io/blog/dark-web-profile-exfilsquad/
  4. https://www.sans.org/blog/hunting-saas-threats-insights-for589-course-cybercriminal-campaigns

ExfilSquad Targets New Victims, Shares Data via Torrents

ExfilSquad targets 13 organizations, exploiting cloud portals for data theft and using torrents to spread stolen information and amplify damage.

Resecurity is tracking the activity of ExfilSquad – the group announced new victims this week. ExfilSquad is a new cybercrime group that emerged in mid-2026. Instead of using ransomware, it steals data and threatens to publish it on a dark web leak site unless victims pay a ransom.

The list includes 13 organizations from the U.S., the UK, and Sweden. Notably, in July, the group also targeted a major financial institution in Nigeria.

“ExfilSquad announced new victims this week and set a firm deadline – August 5, 2026 – to complete all required negotiations. Otherwise, the stolen data will be released. This time, the list of victims includes 13 organizations from the U.S., the UK, and Sweden.” reads the report published by Resecurity. “Notably, in July, the group was also targeting a major financial institution in Nigeria.”

Their TTPs revolve around exploiting cloud/SaaS portals for large-scale data theft, including misconfigured Microsoft Dataverse, Power Pages sites, Case Management and Customer Relationship Management Systems (CRMs).

The collective attracted significant attention after the cyberattack on the U.K.’s Police National Legal Database (PNLD), which compromised contact data of more than 100,000 police officers and criminal justice professionals.

ExfilSquad is leveraging P2P networks to distribute stolen data by using torrent files. Such an approach has already been used by LockBit 3.0 and Cl0p ransomware. Each victim is assigned a unique torrent tracker and an initial web seed, which is a notable tactic employed by the hacking collective.

Resecurity views this tactic as a trend leveraged by sophisticated adversaries involved in ‘hack-and-leak’ operations. By using torrents, the leaked data is easily accessible to a broader audience, including other malicious actors. Due to the decentralized nature of P2P, it is complicated to prevent further data circulating. This amplifies the reputational and financial damage to victim organizations in times, as the data becomes widely available and impossible to remove.

“Once stolen data has been released, it is not possible to stop its sharing via the P2P network or remove the torrent file, because other participants involved in seeding can easily resume downloads. Resecurity views this tactic as a trend leveraged by multiple sophisticated actors involved in hack-and-leak operations.” concludes the report. “Resecurity analyzed the nodes involved in torrent sharing, as well as seeds that participated in the circulation of stolen data. Interestingly, hosts from China and Russia were among the most active during August 7, 2026, which may suggest that the operators behind them had prior knowledge of the data publication or were involved in its distribution at a later stage once it became available. In any case, such hosts indicate an interest in this type of data.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, ExfilSquad)

PNLD Confirms Data Breach Affecting UK Police and Justice Staff

UK police legal database breach exposed officers’ names and work emails, increasing phishing risks. NCA is investigating.

The Police National Legal Database (PNLD), the legal reference system used by all 43 Home Office police forces in England and Wales, confirmed that a data breach exposed the contact details of police officers, staff, and criminal justice professionals and published them on the dark web. The breach also hit Ask the Police, a public Q&A service hosted on the same platform. The National Crime Agency is involved in the investigation.

“Information including the names, organisations and work email addresses of police officers, staff and other criminal justice professionals, government partners and customers has been compromised and published on the dark web.” reads the notice of data breach. “There is no evidence to suggest that passwords or other security credentials have been compromised.”

UK police is investigating the security breach with the help of the National Crime Agency (NCA) and private cybersecurity firms.

The PNLD reported 108,429 police registrations in its 2025-26 annual summary, which gives some sense of the potential user base affected, though PNLD has not disclosed how many individuals are actually in the breached dataset. No victim count, no timeline of when the intrusion began, no statement on how much data was taken.

“The data security incident primarily affected the Police National Legal Database (PNLD) which hosts the Ask the Police site.” continues the notice. “As a result, some names and email addresses of people who have previously submitted a question to Ask the Police have been published on the dark web.”

Ask the Police is a public-facing service where anyone can submit questions to the police. The exposure of those submitters’ names and emails alongside police officers’ work contact details creates two distinct risk categories: named officers are now more vulnerable to targeted phishing, and members of the public who contacted police services have had that fact made visible on criminal forums.

“PNLD also provides legal information, products and services to UK police forces and criminal justice organisations; it is not a crime recording system and does not hold confidential information relating to victims, witnesses, or offenders.” concludes the notice.

All affected organizations were promptly notified, provided guidance, and the incident was reported to the UK Information Commissioner’s Office (ICO).

The extortion group ExfilSquad listed PNLD on its leak site on July 26, though PNLD has not attributed the incident to the group.

Cybersecurity firm VenariX reviewed samples associated with 11 of ExfilSquad’s 15 claimed victims and found structures consistent with Microsoft Dataverse across all of them, pointing toward a likely campaign pattern involving misconfigured Microsoft Power Pages portals, public-facing sites where overly permissive table access settings can expose data to anyone who visits the page without logging in.

PNLD’s 2023-24 annual summary stated the database uses Microsoft Power Platform technology, and the breach notice page references assets on Microsoft’s content.powerapps.com domain, which corroborates the platform connection. That said, neither PNLD’s notice nor VenariX’s report has confirmed a PNLD-specific endpoint, permission setting, or access route, the Power Pages hypothesis remains exactly that: a hypothesis consistent with the evidence, not a confirmed root cause.

“The reviewed data is most consistent with extraction from public Microsoft Power Pages portals that were configured to allow anonymous users to read Dataverse records.” states VenariX. “Microsoft documents that Power Pages can expose Dataverse tables through its portal Web API using the /_api/<EntitySetName> route, and that access is governed by table permissions assigned through web roles.

A likely flow is:

Public Power Pages portal → Anonymous Users web role → Broad table permission → Power Pages Web API or legacy OData feed → Dataverse data export

For any organization running Microsoft Power Pages: VenariX recommends reviewing Anonymous Users table permissions, Web API settings, and legacy OData feeds, then validating access from an unauthenticated browser session. Microsoft provides a tenant-level control that blocks unauthenticated users from reading Dataverse data while still allowing public form submissions. That’s the kind of configuration that should have been validated before deployment, not after a breach.

Police officers and staff whose details were exposed should be alert to targeted phishing that uses their name, organization, and work email, the exact combination now available on the dark web.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, UK Police)

Analog Devices Discloses Data Breach After Unauthorized System Access

Chipmaker Analog Devices disclosed a data breach after detecting unauthorized access to systems on June 23. The investigation is ongoing.

Semiconductor giant Analog Devices (ADI) disclosed a data breach following a cyberattack that resulted in unauthorized access to some of its systems on June 23.

Analog Devices, Inc. (ADI) is a major semiconductor company that designs and manufactures integrated circuits (ICs) used to convert, process, and manage real-world signals in electronic systems.

Unlike companies that mainly produce processors or memory chips, ADI specializes in analog and mixed-signal semiconductors, which act as the bridge between the physical world and digital systems.

Analog Devices immediately activated its incident response plan, involving cybersecurity experts and law enforcement. The company confirmed that certain files were exfiltrated, but the investigation into the scope and nature of the stolen data is still ongoing.

The US company, which generates around $12 billion in annual revenue, reported the incident to the SEC.

“On June 23, 2026, Analog Devices, Inc. (the “Company”) identified unauthorized access to certain Company systems. Following detection of the unauthorized access, the Company immediately activated its incident response protocols and engaged external cybersecurity experts to assist with containment and investigation activities. The Company has also notified and is coordinating with law enforcement authorities. The Company’s operations were not interrupted throughout the duration of the incident.” reads the FORM 8-K report filed with SEC. “The Company’s investigation has found that certain files were exfiltrated from the affected systems. The Company’s investigation into the nature and scope of the exfiltrated information remains ongoing. To the Company’s knowledge, the data has not been publicly released or used for fraudulent purposes. The Company will continue to monitor for any indication of misuse and will take appropriate action if warranted. The Company will provide notifications to affected parties and applicable regulators as appropriate and in accordance with applicable law.”

ADI stated that the information has not been publicly disclosed or misused and that operations were not disrupted. The company does not currently expect a material business impact.

Separately, ADI is reviewing reports of an unrelated cybersecurity incident disclosed on July 26, 2026, to assess its validity, scope, and potential impact.

The report appears linked to the claims made by the cybercrime group ExfilSquad, which announced the theft of over 570,000 records from ADI. However, at this time, Analog Devices is no longer listed on ExfilSquad’s data leak site.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, data breach)

❌