Ransomware victim disclosure
← All victimsUnknown Municipality / CRM (6M records)
Claimed by ExfilSquad · listed 3 hours ago
Status timeline
- ListedSep 5, 2026
- Data leakeddate unknown
At a glance
- Group
- ExfilSquad
- Status
- Data leaked
- Sector
- Government / Municipal
- Listed on leak site
- Sep 5, 2026
- Records
- 6000000
About the victim
AI dossier — public-source company profileUnknown municipality or municipal CRM system operator. The leak post references multiple government entities (UK Department for Education, District of Columbia Public Schools, and unnamed municipal services), suggesting this may be a shared CRM platform or database breach affecting multiple public sector bodies, or a listing of disparate municipal incidents.
- Industry
- Government / Municipal
Attack summary
Severity: critical — Exfiltration of PII at massive scale (6M+ records) from municipal/government systems including resident addresses, identifiers, service history, and student records (children's DOB and home addresses). Involves multiple regulated public sector entities and sensitive personal data of vulnerable populations.ExfilSquad claims exfiltration of approximately 6M records from a municipal CRM system, including resident contact details, service requests, complaint records, addresses, location data, case metadata, and department routing information. The group has published data samples and claims to have compromised multiple public sector entities simultaneously.
Data the group says was taken
AI dossier — extracted from the leak post- resident contact information
- citizen service requests
- home addresses
- phone numbers
- location data
- service case/ticket metadata
- complaint descriptions
- municipal case history
- internal case management data
- department routing information
- service status and resolution information
- student names, dates of birth, addresses (DCPS)
- employee contact records
- authentication data
- access permissions
What the group claims
Large municipal or government entity with resident service request and CRM data.
The leak post
captured from the group's site```
______ __ _ _ _____ _
| ____| / _(_) |/ ____| | |
| |__ __ _| |_ _| | (___ __ _ _ _ __ _ __| |
| __| \ \/ / _| | |\___ \ / _` | | | |/ _` |/ _` |
| |____ > <| | | | |____) | (_| | |_| | (_| | (_| |
|______/_/\_\_| |_|_|_____/ \__, |\__,_|\__,_|\__,_|
| |
|_|
```
We have published all companies that have failed to meet an agreement with us. We'll be back soon with more breaches! Once your companys data is posted here, its NEVER leaving the public eye. Within minutes it will be copied, mirrored, archived, and shared across countless corners of the internet. Once that happens, there is no undo button. The payment we request of you is simply a rounding error compared to the legal fees, regulatory scrutiny, lost contracts, and reputational damage that follow a public data breach. Consider the cost of explaining this to your customers, your partners, your shareholders, and the press. Your customers expect you to protect their information. Your partners expect competence. Your investors expect stability. Once confidence is lost, i…Data the group says was taken
- PII
- resident contact details
- service requests
- complaint descriptions
- addresses
- location data
- case metadata
- ticket metadata
- department routing
- service status
- resolution information
- CRM metadata
Screenshot of the leak post

Sources
Source
Indexed 3 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

