Ransomware victim disclosure
← All victimsAllstate
Claimed by ExfilSquad · listed 3 days ago
Status timeline
- ListedJul 26, 2026
- Data leakeddate unknown
At a glance
- Group
- ExfilSquad
- Status
- Data leaked
- Country
- United States
- Sector
- Financial Services
- Listed on leak site
- Jul 26, 2026
About the victim
AI dossier — public-source company profileAllstate Insurance Company is a major US-based insurance provider offering auto, home, and renters insurance. Headquartered in Northbrook, Illinois, with approximately $67 billion in revenue, it operates nationwide with significant market presence in property and casualty insurance.
- Industry
- Insurance
- Address
- Northbrook, IL
- Founded
- 1931
Attack summary
Severity: critical — Exfiltration of 657K records including significant PII, employee data, and internal account information represents large-scale exposure of regulated sensitive data affecting both customers and employees of a major financial services company.ExfilSquad claims to have exfiltrated approximately 657,000 records containing significant personally identifiable information (PII), recruitment and licensing information, onboarding data, and internal employee account information from Allstate.
Data the group says was taken
AI dossier — extracted from the leak post- personally identifiable information (PII)
- recruitment records
- licensing information
- employee onboarding data
- internal employee account information
What the group claims
Revenue: $67B DATA SUMMARY: 657K~ records containing: significant PII, recruitment and licensing information, onboarding data, and internal employee account information.
Sources
- Victim siteallstate.com
Source
Indexed 3 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

