Ransomware victim disclosure
← All victimsUnknown Education/Admissions Institution
Claimed by ExfilSquad · listed 4 hours ago
Status timeline
- ListedAug 31, 2026
- Data leakeddate unknown
At a glance
- Group
- ExfilSquad
- Status
- Data leaked
- Sector
- Education
- Listed on leak site
- Aug 31, 2026
- Records
- 440000
About the victim
AI dossier — public-source company profileNo specific education/admissions institution can be identified from the leak post. The post lists multiple unrelated victims (Microsoft, UK Department for Education, DCPS, golf companies, airlines, municipalities) across different sectors, not a single educational institution.
Attack summary
Severity: high — Confirmed exfiltration of PII at significant scale (hundreds of thousands of student and staff records), including sensitive data about minors (names, DOB, addresses, school assignments). Multiple educational institutions targeted with publicly disclosed data inventory.ExfilSquad claims exfiltration of data from multiple organizations including education institutions. For the education/admissions sector entries mentioned (UK DfE Help Portal ~600K records, Turing Portal ~7K records, DCPS ~60K student records, and an unnamed institution with ~440K applicant/student records), they claim to have stolen PII, contact information, authentication data, and admissions records.
Data the group says was taken
AI dossier — extracted from the leak post- Parent and staff contact records (names, emails, phone numbers, job titles)
- Student names and dates of birth
- Home addresses and phone numbers
- Student identifiers and school assignments
- Grade levels and registration status
- Applicant and student contact information
- Admissions data
What the group claims
Unnamed institution with applicant and student admissions data exposed.
The leak post
captured from the group's site```
______ __ _ _ _____ _
| ____| / _(_) |/ ____| | |
| |__ __ _| |_ _| | (___ __ _ _ _ __ _ __| |
| __| \ \/ / _| | |\___ \ / _` | | | |/ _` |/ _` |
| |____ > <| | | | |____) | (_| | |_| | (_| | (_| |
|______/_/\_\_| |_|_|_____/ \__, |\__,_|\__,_|\__,_|
| |
|_|
```
We have published all companies that have failed to meet an agreement with us. We'll be back soon with more breaches! Once your companys data is posted here, its NEVER leaving the public eye. Within minutes it will be copied, mirrored, archived, and shared across countless corners of the internet. Once that happens, there is no undo button. The payment we request of you is simply a rounding error compared to the legal fees, regulatory scrutiny, lost contracts, and reputational damage that follow a public data breach. Consider the cost of explaining this to your customers, your partners, your shareholders, and the press. Your customers expect you to protect their information. Your partners expect competence. Your investors expect stability. Once confidence is lost, i…Data the group says was taken
- applicant contact information
- student contact information
- PII
- admissions data
Screenshot of the leak post

Sources
Source
Indexed 4 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

