Ransomware victim disclosure
← All victimsUnknown Municipality/Government (6M records)
Claimed by ExfilSquad · listed 2 hours ago
Status timeline
- ListedAug 21, 2026
- Data leakeddate unknown
At a glance
- Group
- ExfilSquad
- Status
- Data leaked
- Sector
- Government
- Listed on leak site
- Aug 21, 2026
- Records
- 6000000
About the victim
AI dossier — public-source company profileThis is not a single company but a collection of multiple government and public sector organizations (UK government bodies, US school districts, municipalities) whose data ExfilSquad claims to have exfiltrated. The victim name 'Unknown Municipality/Government (6M records)' is a placeholder for what appears to be a multi-victim extortion campaign.
- Industry
- Government & Public Administration
Attack summary
Severity: critical — The post claims exfiltration of significant PII at massive scale (20M+ records) from multiple government entities and critical infrastructure (education, law enforcement, municipal services). Confirmed targets include UK Department for Education, law enforcement, and DC Public Schools with sensitive citizen and student data. This represents confirmed exfiltration of regulated/sensitive data across multiple jurisdictions.ExfilSquad claims to have exfiltrated data from multiple government and public sector entities including UK Department for Education, UK law enforcement, District of Columbia Public Schools, and unnamed municipalities. The group advertises approximately 20+ million records total across all victims, containing significant PII, employee contact information, authentication data, and internal records. The post functions as an extortion threat rather than specific breach evidence.
Data the group says was taken
AI dossier — extracted from the leak post- Citizen and resident PII (names, addresses, phone numbers, dates of birth)
- Employee and staff contact records
- Student records and educational data
- Authentication data and password hashes
- CRM profiles and business account information
- Police force/law enforcement contact records
- Service request and case management data
- Property ownership records
- Customer support histories and transcripts
What the group claims
Unnamed government or municipal entity with resident contact details, service requests, complaint descriptions, and CRM metadata.
The leak post
captured from the group's site```
______ __ _ _ _____ _
| ____| / _(_) |/ ____| | |
| |__ __ _| |_ _| | (___ __ _ _ _ __ _ __| |
| __| \ \/ / _| | |\___ \ / _` | | | |/ _` |/ _` |
| |____ > <| | | | |____) | (_| | |_| | (_| | (_| |
|______/_/\_\_| |_|_|_____/ \__, |\__,_|\__,_|\__,_|
| |
|_|
```
We have published all companies that have failed to meet an agreement with us. We'll be back soon with more breaches! Once your companys data is posted here, its NEVER leaving the public eye. Within minutes it will be copied, mirrored, archived, and shared across countless corners of the internet. Once that happens, there is no undo button. The payment we request of you is simply a rounding error compared to the legal fees, regulatory scrutiny, lost contracts, and reputational damage that follow a public data breach. Consider the cost of explaining this to your customers, your partners, your shareholders, and the press. Your customers expect you to protect their information. Your partners expect competence. Your investors expect stability. Once confidence is lost, i…Data the group says was taken
- PII
- resident contact details
- service requests
- complaint descriptions
- addresses
- location data
- case/ticket metadata
- department routing
- service status
- resolution information
- CRM metadata
Screenshot of the leak post

Sources
Source
Indexed 2 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

