Ransomware victim disclosure
← All victimsUnknown Company 5
Claimed by ExfilSquad · listed 21 hours ago
Status timeline
- ListedAug 23, 2026
- Data leakeddate unknown
At a glance
- Group
- ExfilSquad
- Status
- Data leaked
- Listed on leak site
- Aug 23, 2026
- Records
- 657000
About the victim
AI dossier — public-source company profileUnknown Company 5 is listed in a multi-victim leak post by ExfilSquad but is not specifically identified within the disclosed data summaries. The post aggregates breaches of multiple named entities (Microsoft, UK Department for Education, TaylorMade, airlines, DC Public Schools, and municipal services) but does not clearly delineate which dataset corresponds to 'Unknown Company 5'.
Attack summary
Severity: medium — The leak post advertises exfiltration of significant PII, authentication data, and business records across multiple victims, and data is published. However, because Unknown Company 5 is not explicitly identified in the post, the specific data types, volume, and sensitivity relevant to this entity cannot be determined. Conservative medium rating pending clarification.ExfilSquad claims to have exfiltrated data from multiple organizations in a coordinated campaign. The group does not specify which dataset belongs to Unknown Company 5, making it impossible to determine the exact scope or nature of the alleged compromise affecting this entity.
What the group claims
Victim with recruitment, licensing, onboarding, and employee account data.
The leak post
captured from the group's site```
______ __ _ _ _____ _
| ____| / _(_) |/ ____| | |
| |__ __ _| |_ _| | (___ __ _ _ _ __ _ __| |
| __| \ \/ / _| | |\___ \ / _` | | | |/ _` |/ _` |
| |____ > <| | | | |____) | (_| | |_| | (_| | (_| |
|______/_/\_\_| |_|_|_____/ \__, |\__,_|\__,_|\__,_|
| |
|_|
```
We have published all companies that have failed to meet an agreement with us. We'll be back soon with more breaches! Once your companys data is posted here, its NEVER leaving the public eye. Within minutes it will be copied, mirrored, archived, and shared across countless corners of the internet. Once that happens, there is no undo button. The payment we request of you is simply a rounding error compared to the legal fees, regulatory scrutiny, lost contracts, and reputational damage that follow a public data breach. Consider the cost of explaining this to your customers, your partners, your shareholders, and the press. Your customers expect you to protect their information. Your partners expect competence. Your investors expect stability. Once confidence is lost, i…Data the group says was taken
- PII
- recruitment information
- licensing information
- onboarding data
- internal employee account information
Screenshot of the leak post

Sources
Source
Indexed 21 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

