Ransomware victim disclosure
← All victimsUnknown Enterprise Company
Claimed by ExfilSquad · listed 5 days ago
Status timeline
- ListedAug 13, 2026
- Data leakeddate unknown
At a glance
- Group
- ExfilSquad
- Status
- Data leaked
- Listed on leak site
- Aug 13, 2026
- Records
- 430000
About the victim
AI dossier — public-source company profileNo specific company can be identified from this leak post. The victim name 'Unknown Enterprise Company' is a placeholder.
Attack summary
Severity: critical — Post claims exfiltration of 20M+ records across multiple organizations including government agencies (UK DoE, DC Schools, DCPS), educational institutions, and major corporations. Includes confirmed sensitive data: student records with dates of birth and home addresses, law enforcement contacts, financial information, and significant PII at scale. Multiple regulated sectors (education, government) affected.ExfilSquad claims to have breached multiple organizations (Microsoft, UK Department for Education, TaylorMade, District of Columbia Public Schools, and others) and exfiltrated millions of records containing PII, authentication data, and sensitive business information. The group has published data and threatens continued disclosure.
Data the group says was taken
AI dossier — extracted from the leak post- personally identifiable information (PII)
- employee contact records
- customer contact information
- authentication credentials and password hashes
- portal identities and account information
- CRM user profiles
- financial and billing data
- student records (names, dates of birth, addresses, identifiers)
- law enforcement contact records
- travel and flight information
- property ownership records
- internal service tickets
- access permissions
What the group claims
Company with customer and partner contact information breached.
The leak post
captured from the group's site```
______ __ _ _ _____ _
| ____| / _(_) |/ ____| | |
| |__ __ _| |_ _| | (___ __ _ _ _ __ _ __| |
| __| \ \/ / _| | |\___ \ / _` | | | |/ _` |/ _` |
| |____ > <| | | | |____) | (_| | |_| | (_| | (_| |
|______/_/\_\_| |_|_|_____/ \__, |\__,_|\__,_|\__,_|
| |
|_|
```
We have published all companies that have failed to meet an agreement with us. We'll be back soon with more breaches! Once your companys data is posted here, its NEVER leaving the public eye. Within minutes it will be copied, mirrored, archived, and shared across countless corners of the internet. Once that happens, there is no undo button. The payment we request of you is simply a rounding error compared to the legal fees, regulatory scrutiny, lost contracts, and reputational damage that follow a public data breach. Consider the cost of explaining this to your customers, your partners, your shareholders, and the press. Your customers expect you to protect their information. Your partners expect competence. Your investors expect stability. Once confidence is lost, i…Data the group says was taken
- customer contact information
- partner contact information
- PII
- enterprise account identifiers
Screenshot of the leak post

Sources
Source
Indexed 5 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

