Ransomware victim disclosure
← All victimsUnknown Municipality / Government (3M records)
Claimed by ExfilSquad · listed 6 hours ago
Status timeline
- ListedAug 19, 2026
- Data leakeddate unknown
At a glance
- Group
- ExfilSquad
- Status
- Data leaked
- Listed on leak site
- Aug 19, 2026
- Records
- 3000000
About the victim
AI dossier — public-source company profileThe victim listing aggregates multiple government and public-sector entities across the United States and UK, including federal departments, local school districts, municipal services, law enforcement, and education portals. No single entity can be identified from the generic victim_name 'Unknown Municipality / Government'.
- Industry
- Government / Public Services
Attack summary
Severity: critical — Confirmed exfiltration of large-scale regulated and sensitive data: student records (including minors' PII), government employee records, law enforcement contact data, and citizen service records. Multiple government agencies and educational institutions affected. Government sector data involving children and critical infrastructure administration represents highest sensitivity.ExfilSquad claims to have exfiltrated data from multiple government and public-sector organisations totalling approximately 3M records in the primary victim entry. The group published detailed summaries of breaches affecting Microsoft, UK Department for Education, US law enforcement, DC Public Schools, and various municipal and educational institutions, claiming access to significant PII, authentication data, CRM records, student information, and internal service records.
Data the group says was taken
AI dossier — extracted from the leak post- Significant PII (names, contact details, addresses)
- Employee and customer contact information
- Authentication data and password hashes
- Student records (names, dates of birth, school assignments)
- Law enforcement contact records
- Parent and staff contact information
- CRM user profiles and business identifiers
- Service requests and complaint records
- Property ownership and warranty records
- Travel and flight information
- Financial and account information
- Internal service tickets and access permissions
What the group claims
Municipal entity with citizen service requests, addresses, and internal case management data.
The leak post
captured from the group's site```
______ __ _ _ _____ _
| ____| / _(_) |/ ____| | |
| |__ __ _| |_ _| | (___ __ _ _ _ __ _ __| |
| __| \ \/ / _| | |\___ \ / _` | | | |/ _` |/ _` |
| |____ > <| | | | |____) | (_| | |_| | (_| | (_| |
|______/_/\_\_| |_|_|_____/ \__, |\__,_|\__,_|\__,_|
| |
|_|
```
We have published all companies that have failed to meet an agreement with us. We'll be back soon with more breaches! Once your companys data is posted here, its NEVER leaving the public eye. Within minutes it will be copied, mirrored, archived, and shared across countless corners of the internet. Once that happens, there is no undo button. The payment we request of you is simply a rounding error compared to the legal fees, regulatory scrutiny, lost contracts, and reputational damage that follow a public data breach. Consider the cost of explaining this to your customers, your partners, your shareholders, and the press. Your customers expect you to protect their information. Your partners expect competence. Your investors expect stability. Once confidence is lost, i…Data the group says was taken
- PII
- citizen service requests
- addresses
- municipal case history
- internal case management data
Screenshot of the leak post

Sources
Source
Indexed 6 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

