Ransomware victim disclosure
← All victimsUnknown Municipality / City Government 1
Claimed by ExfilSquad · listed 3 hours ago
Status timeline
- ListedSep 6, 2026
- Data leakeddate unknown
At a glance
- Group
- ExfilSquad
- Status
- Data leaked
- Sector
- Government / Municipal
- Listed on leak site
- Sep 6, 2026
- Records
- 6000000
About the victim
AI dossier — public-source company profileThe victim is listed as 'Unknown Municipality / City Government' in this leak post. No specific municipality, city, or agency name is disclosed in the available post excerpt. The group claims exfiltration from multiple distinct entities including UK government departments, US school districts, airlines, and municipal services, but the specific identity of the primary victim remains unconfirmed.
- Industry
- Government / Municipal
Attack summary
Severity: critical — Multiple confirmed exfiltrations of highly regulated government and municipal data at massive scale (6M+ records from single entities), including student PII, law enforcement records, citizen service data, and educational records. This involves sensitive government and educational sectors with strict regulatory requirements (FERPA, GDPR, etc.).ExfilSquad claims to have exfiltrated data from multiple government and municipal entities. The post lists numerous datasets across education, law enforcement, municipal services, and other sectors, totaling millions of records containing PII, contact information, authentication data, and internal service records. No specific ransom demand or payment figure is stated in the excerpt.
Data the group says was taken
AI dossier — extracted from the leak post- Significant PII (names, contact details, addresses)
- Employee and customer contact information
- Authentication data and password hashes
- Student records (names, DOB, addresses, school assignments)
- Law enforcement contact records
- Municipal service requests and case history
- Property ownership records
- Portal identities and corporate account information
- CRM profiles and account identifiers
What the group claims
Resident service requests, complaints, CRM and location data from a municipal entity.
The leak post
captured from the group's site```
______ __ _ _ _____ _
| ____| / _(_) |/ ____| | |
| |__ __ _| |_ _| | (___ __ _ _ _ __ _ __| |
| __| \ \/ / _| | |\___ \ / _` | | | |/ _` |/ _` |
| |____ > <| | | | |____) | (_| | |_| | (_| | (_| |
|______/_/\_\_| |_|_|_____/ \__, |\__,_|\__,_|\__,_|
| |
|_|
```
We have published all companies that have failed to meet an agreement with us. We'll be back soon with more breaches! Once your companys data is posted here, its NEVER leaving the public eye. Within minutes it will be copied, mirrored, archived, and shared across countless corners of the internet. Once that happens, there is no undo button. The payment we request of you is simply a rounding error compared to the legal fees, regulatory scrutiny, lost contracts, and reputational damage that follow a public data breach. Consider the cost of explaining this to your customers, your partners, your shareholders, and the press. Your customers expect you to protect their information. Your partners expect competence. Your investors expect stability. Once confidence is lost, i…Data the group says was taken
- PII
- resident contact details
- service requests
- complaint descriptions
- addresses
- location data
- case/ticket metadata
- department routing
- service status
- resolution information
- CRM metadata
Screenshot of the leak post

Sources
Source
Indexed 3 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

