Ransomware victim disclosure
← All victimsUnknown Municipality/City (6M records)
Claimed by ExfilSquad · listed 2 days ago
Status timeline
- ListedSep 11, 2026
- Data leakeddate unknown
At a glance
- Group
- ExfilSquad
- Status
- Data leaked
- Sector
- Government
- Listed on leak site
- Sep 11, 2026
- Records
- 6000000
About the victim
AI dossier — public-source company profileUnknown municipality or city government entity. The leak post references multiple confirmed government victims (UK Department for Education, District of Columbia Public Schools, and unnamed municipal services), suggesting the victim may be a city or regional administration providing resident services, public education, or municipal administration.
- Industry
- Government / Public Administration
Attack summary
Severity: critical — Confirmed exfiltration of large-scale PII from government/municipal systems affecting millions of residents and students. Includes sensitive personal data, home addresses, and children's educational records. Multiple government entities explicitly named in post. Represents regulatory breach of government data protection obligations.ExfilSquad claims to have exfiltrated data from one or more municipal/government entities. The group published multiple government victims' data including approximately 6M resident records from at least one municipality containing PII, service requests, addresses, and CRM metadata, along with 3M citizen service request records and 60K student records from school systems.
Data the group says was taken
AI dossier — extracted from the leak post- Resident personal identifiable information (PII)
- Citizen service request records
- Home addresses and location data
- Phone numbers and email addresses
- Municipal case/ticket metadata
- CRM records
- Student names and dates of birth
- School assignment and grade information
- Complaint descriptions
- Service status and resolution information
What the group claims
Unnamed municipal government with resident service request and CRM data breach.
The leak post
captured from the group's site```
______ __ _ _ _____ _
| ____| / _(_) |/ ____| | |
| |__ __ _| |_ _| | (___ __ _ _ _ __ _ __| |
| __| \ \/ / _| | |\___ \ / _` | | | |/ _` |/ _` |
| |____ > <| | | | |____) | (_| | |_| | (_| | (_| |
|______/_/\_\_| |_|_|_____/ \__, |\__,_|\__,_|\__,_|
| |
|_|
```
We have published all companies that have failed to meet an agreement with us. We'll be back soon with more breaches! Once your companys data is posted here, its NEVER leaving the public eye. Within minutes it will be copied, mirrored, archived, and shared across countless corners of the internet. Once that happens, there is no undo button. The payment we request of you is simply a rounding error compared to the legal fees, regulatory scrutiny, lost contracts, and reputational damage that follow a public data breach. Consider the cost of explaining this to your customers, your partners, your shareholders, and the press. Your customers expect you to protect their information. Your partners expect competence. Your investors expect stability. Once confidence is lost, i…Data the group says was taken
- PII
- resident contact details
- service requests
- complaint descriptions
- addresses
- location data
- case/ticket metadata
- department routing
- service status
- resolution information
- CRM metadata
Screenshot of the leak post

Sources
Source
Indexed 2 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

