Ransomware victim disclosure
← All victimsUnknown Municipality / Case Management (3M records)
Claimed by ExfilSquad · listed 1 day ago
Status timeline
- ListedSep 5, 2026
- Data leakeddate unknown
At a glance
- Group
- ExfilSquad
- Status
- Data leaked
- Sector
- Government / Municipal
- Listed on leak site
- Sep 5, 2026
- Records
- 3000000
About the victim
AI dossier — public-source company profileAn unknown municipality operating a case management system handling citizen service requests, complaints, and administrative records. The organization maintains records across multiple departments and service areas.
- Industry
- Government / Municipal
Attack summary
Severity: critical — Confirmed exfiltration of 3M+ records containing significant PII and sensitive municipal data (addresses, case histories) affecting citizens at scale. Municipal/government data exposure is regulated and creates substantial harm to individuals and institutional trust.ExfilSquad claims to have exfiltrated approximately 3 million records from a municipal case management system, including significant personally identifiable information (PII), citizen service requests, addresses, municipal case history, and internal case management data. The group has published the data.
Data the group says was taken
AI dossier — extracted from the leak post- Citizen PII (names, addresses, phone numbers)
- Service request records
- Case management data
- Case/ticket metadata
- Department routing information
- Complaint descriptions
- Service status and resolution records
- CRM metadata
What the group claims
Municipal entity with citizen service requests and case management data.
The leak post
captured from the group's site```
______ __ _ _ _____ _
| ____| / _(_) |/ ____| | |
| |__ __ _| |_ _| | (___ __ _ _ _ __ _ __| |
| __| \ \/ / _| | |\___ \ / _` | | | |/ _` |/ _` |
| |____ > <| | | | |____) | (_| | |_| | (_| | (_| |
|______/_/\_\_| |_|_|_____/ \__, |\__,_|\__,_|\__,_|
| |
|_|
```
We have published all companies that have failed to meet an agreement with us. We'll be back soon with more breaches! Once your companys data is posted here, its NEVER leaving the public eye. Within minutes it will be copied, mirrored, archived, and shared across countless corners of the internet. Once that happens, there is no undo button. The payment we request of you is simply a rounding error compared to the legal fees, regulatory scrutiny, lost contracts, and reputational damage that follow a public data breach. Consider the cost of explaining this to your customers, your partners, your shareholders, and the press. Your customers expect you to protect their information. Your partners expect competence. Your investors expect stability. Once confidence is lost, i…Data the group says was taken
- PII
- citizen service requests
- addresses
- municipal case history
- internal case management data
Screenshot of the leak post

Sources
Source
Indexed 1 day agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

