Ransomware victim disclosure
← All victimsUnknown Airline/Travel Company
Claimed by ExfilSquad · listed 2 hours ago
Status timeline
- ListedAug 10, 2026
- Data leakeddate unknown
At a glance
- Group
- ExfilSquad
- Status
- Data leaked
- Sector
- Travel / Aviation
- Listed on leak site
- Aug 10, 2026
- Records
- 2400000
About the victim
AI dossier — public-source company profileUnknown airline or travel company. Limited identifying information available from the leak post; the group references multiple victims but does not clearly isolate which specific airline/travel entity is the primary subject.
- Industry
- Travel / Aviation
Attack summary
Severity: critical — Confirmed exfiltration of 2.4M records containing significant PII and sensitive travel/operational data from a transportation sector entity. Scale and nature of data (customer information, travel history) poses high regulatory and reputational risk.ExfilSquad claims to have exfiltrated approximately 2.4M records including customer PII, flight and travel information, complaint records, baggage details, and customer support communications. The group states data will be published and distributed across the internet.
Data the group says was taken
AI dossier — extracted from the leak post- customer PII
- flight and travel information
- complaint records
- baggage details
- customer support email communications
What the group claims
Company with 2.4M records containing flight, travel, and customer support data.
The leak post
captured from the group's site```
______ __ _ _ _____ _
| ____| / _(_) |/ ____| | |
| |__ __ _| |_ _| | (___ __ _ _ _ __ _ __| |
| __| \ \/ / _| | |\___ \ / _` | | | |/ _` |/ _` |
| |____ > <| | | | |____) | (_| | |_| | (_| | (_| |
|______/_/\_\_| |_|_|_____/ \__, |\__,_|\__,_|\__,_|
| |
|_|
```
We have published all companies that have failed to meet an agreement with us. We'll be back soon with more breaches! Once your companys data is posted here, its NEVER leaving the public eye. Within minutes it will be copied, mirrored, archived, and shared across countless corners of the internet. Once that happens, there is no undo button. The payment we request of you is simply a rounding error compared to the legal fees, regulatory scrutiny, lost contracts, and reputational damage that follow a public data breach. Consider the cost of explaining this to your customers, your partners, your shareholders, and the press. Your customers expect you to protect their information. Your partners expect competence. Your investors expect stability. Once confidence is lost, i…Data the group says was taken
- PII
- customer support cases
- flight and travel information
- complaint records
- baggage details
- customer support email communications
Screenshot of the leak post

Sources
Source
Indexed 2 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

