ExfilSquad Adds New Victims and Uses Torrents to Publish Data Stolen from Cloud Portals

Views: 47 views

437/69 Thursday, August 13, 2026

Resecurity has published a report tracking the activities of ExfilSquad, a cybercrime group that emerged in mid-2026. The group uses a data theft and extortion model, threatening to publish stolen information on a dark web leak site if victims refuse to pay ransom, rather than deploying ransomware to encrypt systems. Most recently, ExfilSquad listed 13 new victim organizations in the United States, the United Kingdom, and Sweden, setting a negotiation deadline of August 5, 2026, before releasing the stolen data. In July, the group also targeted a major financial institution in Nigeria.

According to Resecurity, ExfilSquad’s tactics, techniques, and procedures (TTPs) focus on exploiting cloud portals and SaaS portals to steal large volumes of data, especially from misconfigured systems such as Microsoft Dataverse, Power Pages sites, case management systems, and Customer Relationship Management (CRM) platforms. The group gained significant attention after the attack on the United Kingdom’s Police National Legal Database (PNLD), which compromised contact information belonging to more than 100,000 police officers and justice sector personnel.

ExfilSquad also uses peer-to-peer (P2P) networks through torrent files to distribute stolen data, a technique previously seen in LockBit 3.0 and Cl0p ransomware operations. Each victim is assigned a dedicated torrent tracker and web seed to broaden access to the leaked data. Resecurity assesses that this approach is increasingly being adopted in hack-and-leak operations because once data is released through a P2P network, controlling its distribution or removing it becomes extremely difficult. Other users can continue seeding and downloading the data, increasing reputational and financial damage to victim organizations. Resecurity also stated that analysis of related nodes and seeds found high activity from hosts in China and Russia on August 7, 2026, which may indicate interest in the data or involvement in its distribution after publication.

Source: https://securityaffairs.com/197025/security/exfilsquad-targets-new-victims-shares-data-via-torrents.html