Ransomware victim disclosure
← All victimsUnknown Municipality/CRM (6M records)
Claimed by ExfilSquad · listed 3 days ago
Status timeline
- ListedAug 15, 2026
- Data leakeddate unknown
At a glance
- Group
- ExfilSquad
- Status
- Data leaked
- Sector
- Government
- Listed on leak site
- Aug 15, 2026
- Records
- 6000000
About the victim
AI dossier — public-source company profileUnknown municipality operating CRM systems for citizen service requests, complaint management, and municipal case handling. The victim name suggests a local government entity with significant digital infrastructure managing resident data at scale.
- Industry
- Government / Municipal Services
Attack summary
Severity: critical — Confirmed exfiltration of 6M records of government/municipal resident data including PII at massive scale, addresses, location data, and service history. Government sector with sensitive citizen information meets critical threshold. The leak post also lists multiple other critical breaches (UK Department for Education, law enforcement, schools, airlines) published in the same disclosure.ExfilSquad claims exfiltration of approximately 6 million municipal records containing resident PII, service request details, addresses, location data, case metadata, and CRM information. The group has published the data and states it will not be removed.
Data the group says was taken
AI dossier — extracted from the leak post- Resident contact details
- Service requests and complaints
- Physical addresses
- Location data
- Case/ticket metadata
- Department routing information
- Service status records
- Resolution information
- CRM metadata
- Significant PII
What the group claims
Unnamed municipal or government entity with resident service requests and CRM data.
The leak post
captured from the group's site```
______ __ _ _ _____ _
| ____| / _(_) |/ ____| | |
| |__ __ _| |_ _| | (___ __ _ _ _ __ _ __| |
| __| \ \/ / _| | |\___ \ / _` | | | |/ _` |/ _` |
| |____ > <| | | | |____) | (_| | |_| | (_| | (_| |
|______/_/\_\_| |_|_|_____/ \__, |\__,_|\__,_|\__,_|
| |
|_|
```
We have published all companies that have failed to meet an agreement with us. We'll be back soon with more breaches! Once your companys data is posted here, its NEVER leaving the public eye. Within minutes it will be copied, mirrored, archived, and shared across countless corners of the internet. Once that happens, there is no undo button. The payment we request of you is simply a rounding error compared to the legal fees, regulatory scrutiny, lost contracts, and reputational damage that follow a public data breach. Consider the cost of explaining this to your customers, your partners, your shareholders, and the press. Your customers expect you to protect their information. Your partners expect competence. Your investors expect stability. Once confidence is lost, i…Data the group says was taken
- PII
- resident contact details
- service requests
- complaint descriptions
- addresses
- location data
- case metadata
- department routing
- service status
- resolution information
- CRM metadata
Screenshot of the leak post

Sources
Source
Indexed 3 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

