Ransomware victim disclosure
← All victimsUnknown University / Admissions Entity
Claimed by ExfilSquad · listed 3 hours ago
Status timeline
- ListedSep 5, 2026
- Data leakeddate unknown
At a glance
- Group
- ExfilSquad
- Status
- Data leaked
- Sector
- Education
- Listed on leak site
- Sep 5, 2026
- Records
- 440000
Attack summary
Severity: critical — Multiple confirmed exfiltrations of regulated data: UK Department for Education (student PII including minors' home addresses), District of Columbia Public Schools (student records), law enforcement contact data, and large-scale customer/employee PII across private sector. Involves government entities and education institutions with sensitive personal data on vulnerable populations.This is not a single company breach. The leak post is a mass disclosure by ExfilSquad listing multiple confirmed victims across education, government, golf, aviation, and municipal sectors. The group claims exfiltration of PII, authentication data, employee records, customer information, and internal business data from at least 10+ distinct organizations.
Data the group says was taken
AI dossier — extracted from the leak post- Personal Identifiable Information (PII) at scale
- Employee contact and authentication data
- Customer account and support records
- Password hashes and authentication credentials
- Student records including dates of birth and home addresses
- Law enforcement officer contact records
- Government service request data
- Flight and travel information
- Property ownership records
- Internal service tickets and CRM data
What the group claims
Unnamed institution with applicant and student admissions data.
The leak post
captured from the group's site```
______ __ _ _ _____ _
| ____| / _(_) |/ ____| | |
| |__ __ _| |_ _| | (___ __ _ _ _ __ _ __| |
| __| \ \/ / _| | |\___ \ / _` | | | |/ _` |/ _` |
| |____ > <| | | | |____) | (_| | |_| | (_| | (_| |
|______/_/\_\_| |_|_|_____/ \__, |\__,_|\__,_|\__,_|
| |
|_|
```
We have published all companies that have failed to meet an agreement with us. We'll be back soon with more breaches! Once your companys data is posted here, its NEVER leaving the public eye. Within minutes it will be copied, mirrored, archived, and shared across countless corners of the internet. Once that happens, there is no undo button. The payment we request of you is simply a rounding error compared to the legal fees, regulatory scrutiny, lost contracts, and reputational damage that follow a public data breach. Consider the cost of explaining this to your customers, your partners, your shareholders, and the press. Your customers expect you to protect their information. Your partners expect competence. Your investors expect stability. Once confidence is lost, i…Data the group says was taken
- applicant contact information
- student contact information
- PII
- admissions data
Screenshot of the leak post

Sources
Source
Indexed 3 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

