Ransomware victim disclosure
← All victimsMicrosoft
Claimed by ExfilSquad · listed 3 days ago
Status timeline
- ListedJul 26, 2026
- Data leakeddate unknown
At a glance
- Group
- ExfilSquad
- Status
- Data leaked
- Country
- United States
- Sector
- Technology
- Listed on leak site
- Jul 26, 2026
About the victim
AI dossier — public-source company profileMicrosoft Corporation is a multinational technology company headquartered in Redmond, Washington, with annual revenue of approximately $318 billion. The company develops and sells software, cloud services, and hardware products including Windows, Office 365, Azure, and Xbox to consumers and enterprises globally.
- Industry
- Cloud Computing, Software & Enterprise Services
- Founded
- 1975
Attack summary
Severity: critical — Claimed exfiltration of 8 million records including PII at massive scale, authentication credentials, password hashes, and internal access data from a major technology company serving hundreds of millions of users globally. Exposure of this scope and sensitivity poses systemic risk to Microsoft's customers and operations.ExfilSquad claims to have exfiltrated approximately 8 million records from Microsoft containing significant personally identifiable information, employee and customer contact data, authentication credentials, password hashes, portal identities, corporate accounts, business leads, facilities records, service tickets, and access permissions.
Data the group says was taken
AI dossier — extracted from the leak post- PII (personally identifiable information)
- employee contact information
- customer contact information
- authentication data
- password hashes
- portal identities
- corporate account information
- business leads
- facilities management records
- internal service tickets
- access permissions
What the group claims
Revenue: $318B DATA SUMMARY: 8M~ records containing: significant PII, employee and customer contact information, authentication data, password hashes, portal identities, corporate account information, business leads, facilities management records, internal service tickets, and access permissions.
Sources
- Victim sitemicrosoft.com
Source
Indexed 3 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

