Ransomware victim disclosure
← All victimsUnknown Municipality/CRM Entity (6M records)
Claimed by ExfilSquad · listed 4 days ago
Status timeline
- ListedSep 1, 2026
- Data leakeddate unknown
At a glance
- Group
- ExfilSquad
- Status
- Data leaked
- Sector
- Government
- Listed on leak site
- Sep 1, 2026
- Records
- 6000000
About the victim
AI dossier — public-source company profileThe victim name 'Unknown Municipality/CRM Entity (6M records)' refers to one or more municipal or government agencies operating CRM systems. The leak post lists multiple distinct breaches across different government and private entities, but the primary victim indexed here appears to be a municipality managing citizen services, with 6M records of resident contact details, service requests, and case management data.
- Industry
- Government / Municipal Services
Attack summary
Severity: critical — Confirmed exfiltration of large-scale PII (6M municipal resident records including names, addresses, phone numbers, location data) from a government entity represents sensitive personal information at scale affecting civilians, plus exposure of municipal service infrastructure data. Additional breaches listed (UK Department for Education, DCPS, law enforcement records) compounds the critical assessment.ExfilSquad claims to have exfiltrated data from multiple organizations including government agencies, educational institutions, and private companies. For the primary municipal victim (6M records), the group claims access to resident PII, service requests, addresses, location data, and extensive CRM metadata. The post includes no ransom demand figure, only a manifesto on reputational and regulatory costs of data breaches.
Data the group says was taken
AI dossier — extracted from the leak post- Significant PII (names, addresses, phone numbers)
- Resident/citizen contact details
- Service requests and complaint descriptions
- Location data and property information
- Case and ticket metadata
- Department routing information
- Service status and resolution records
- CRM system data
What the group claims
Large municipal/government entity with resident service request and CRM data leaked.
The leak post
captured from the group's site```
______ __ _ _ _____ _
| ____| / _(_) |/ ____| | |
| |__ __ _| |_ _| | (___ __ _ _ _ __ _ __| |
| __| \ \/ / _| | |\___ \ / _` | | | |/ _` |/ _` |
| |____ > <| | | | |____) | (_| | |_| | (_| | (_| |
|______/_/\_\_| |_|_|_____/ \__, |\__,_|\__,_|\__,_|
| |
|_|
```
We have published all companies that have failed to meet an agreement with us. We'll be back soon with more breaches! Once your companys data is posted here, its NEVER leaving the public eye. Within minutes it will be copied, mirrored, archived, and shared across countless corners of the internet. Once that happens, there is no undo button. The payment we request of you is simply a rounding error compared to the legal fees, regulatory scrutiny, lost contracts, and reputational damage that follow a public data breach. Consider the cost of explaining this to your customers, your partners, your shareholders, and the press. Your customers expect you to protect their information. Your partners expect competence. Your investors expect stability. Once confidence is lost, i…Data the group says was taken
- PII
- resident contact details
- service requests
- complaint descriptions
- addresses
- location data
- case/ticket metadata
- department routing
- service status
- resolution information
- CRM metadata
Screenshot of the leak post

Sources
Source
Indexed 4 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

