Ransomware victim disclosure
← All victimsTaylorMade Golf Company
listed as TaylorMade & Sun Day Red golf · Claimed by ExfilSquad · listed 3 days ago
Status timeline
- ListedJul 26, 2026
- Data leakeddate unknown
At a glance
- Group
- ExfilSquad
- Status
- Data leaked
- Country
- United States
- Sector
- Retail & E-Commerce
- Listed on leak site
- Jul 26, 2026
About the victim
AI dossier — public-source company profileTaylorMade Golf is a major manufacturer and retailer of golf clubs, balls, bags, and apparel. The company operates globally through direct e-commerce (taylormadegolf.com) and wholesale channels. With stated revenue of $1.5B, it is one of the largest golf equipment brands in the world.
- Industry
- Golf Equipment & Apparel Manufacturing and Retail
- Founded
- 1979
Attack summary
Severity: critical — Confirmed exfiltration of ~2M records containing regulated PII at scale (customer names, addresses, payment data), combined with financial and account information. This represents significant exposure of consumer data subject to state privacy laws and payment card regulations.ExfilSquad claims to have exfiltrated approximately 2 million records from TaylorMade Golf, including customer PII, order history, shipping data, business account credentials, financial information, internal notes, and AI support chat transcripts. The group has published the data without stated ransom demand.
Data the group says was taken
AI dossier — extracted from the leak post- customer personally identifiable information (PII)
- customer support history
- order records
- shipping information
- business account data
- financial/account information
- internal notes
- email attachments
- AI support chat transcripts
What the group claims
Revenue: $1.5B DATA SUMMARY: 2M~ records containing: significant PII, customer support history, orders, shipping information, business account data, financial/account information, internal notes, attachments, and AI support chat transcripts.
Sources
- Victim sitetaylormadegolf.com
Source
Indexed 3 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

