Ransomware victim disclosure
← All victimsViavi Solutions
Claimed by ExfilSquad · listed 3 days ago
Status timeline
- ListedJul 26, 2026
- Data leakeddate unknown
At a glance
- Group
- ExfilSquad
- Status
- Data leaked
- Country
- United States
- Sector
- Technology
- Listed on leak site
- Jul 26, 2026
About the victim
AI dossier — public-source company profileVIAVI Solutions is a global provider of network testing, monitoring, and assurance solutions for telecommunications, wireless, fiber, and enterprise networks. The company serves telecom operators, equipment manufacturers, and enterprises with lab equipment, field instruments, and software-based assurance platforms across 5G, optical, and broadband infrastructure.
- Industry
- Network Test, Monitoring & Assurance / Telecommunications Equipment
Attack summary
Severity: high — Confirmed exfiltration of 430K records at scale including significant PII and enterprise identifiers affecting customers and partners of a major B2B technology vendor. High reputational and operational risk despite no ransomware encryption mentioned.ExfilSquad claims to have exfiltrated approximately 430,000 records containing customer and partner contact information, significant PII, and enterprise account identifiers from VIAVI Solutions. The group has published the data.
Data the group says was taken
AI dossier — extracted from the leak post- Customer contact information
- Partner contact information
- Personally identifiable information (PII)
- Enterprise account identifiers
What the group claims
Revenue: $1B DATA SUMMARY: 430K~ records containing: customer and partner contact information, significant PII, and enterprise account identifiers.
Sources
- Victim siteviavisolutions.com
Source
Indexed 3 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

