Ransomware victim disclosure
← All victimsUnknown Municipal / CRM 1
Claimed by ExfilSquad · listed 2 hours ago
Status timeline
- ListedAug 25, 2026
- Data leakeddate unknown
At a glance
- Group
- ExfilSquad
- Status
- Data leaked
- Sector
- Government / Municipal
- Listed on leak site
- Aug 25, 2026
- Records
- 6000000
About the victim
AI dossier — public-source company profileUnknown municipal or government CRM system operator. The victim_name indicates a generic municipal/CRM entity with no identifying details in the leak post itself.
Attack summary
Severity: critical — Post lists multiple confirmed exfiltrations of regulated and sensitive data at scale: UK government education portals (~607K records), law enforcement contacts (135K records), school records including minors' PII (60K-440K records), and municipal/government citizen service data (3M-6M records). Includes significant PII, authentication credentials, and government/education sector data.ExfilSquad claims to have exfiltrated data from multiple entities. The leak post lists numerous organizations (Microsoft, UK Department for Education, TaylorMade, airlines, school districts, municipalities) with varying data volumes and types, suggesting a broad campaign rather than a single 'Unknown Municipal / CRM 1' victim.
Data the group says was taken
AI dossier — extracted from the leak post- significant PII
- employee and customer contact information
- authentication data
- password hashes
- portal identities
- corporate account information
- CRM user profiles
- student names and dates of birth
- home addresses
- phone numbers
- email addresses
- job titles
- police force contact records
- recruitment and licensing information
- shipping and order information
- financial/account information
- support chat transcripts
- travel and flight information
- property ownership records
- municipal case history
- service request data
What the group claims
Large municipal CRM breach with resident service requests, complaints, and case management data.
The leak post
captured from the group's site```
______ __ _ _ _____ _
| ____| / _(_) |/ ____| | |
| |__ __ _| |_ _| | (___ __ _ _ _ __ _ __| |
| __| \ \/ / _| | |\___ \ / _` | | | |/ _` |/ _` |
| |____ > <| | | | |____) | (_| | |_| | (_| | (_| |
|______/_/\_\_| |_|_|_____/ \__, |\__,_|\__,_|\__,_|
| |
|_|
```
We have published all companies that have failed to meet an agreement with us. We'll be back soon with more breaches! Once your companys data is posted here, its NEVER leaving the public eye. Within minutes it will be copied, mirrored, archived, and shared across countless corners of the internet. Once that happens, there is no undo button. The payment we request of you is simply a rounding error compared to the legal fees, regulatory scrutiny, lost contracts, and reputational damage that follow a public data breach. Consider the cost of explaining this to your customers, your partners, your shareholders, and the press. Your customers expect you to protect their information. Your partners expect competence. Your investors expect stability. Once confidence is lost, i…Data the group says was taken
- PII
- resident contact details
- service requests
- complaint descriptions
- addresses
- location data
- case metadata
- ticket metadata
- department routing
- service status
- resolution information
- CRM metadata
Screenshot of the leak post

Sources
Source
Indexed 2 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

