ExfilSquad’s reported addition of 13 organizations to its extortion site should be treated as a claim set, not a confirmed victim list—but the group’s use of torrent-based publication raises the stakes for incident responders once stolen files begin circulating beyond a leak portal. The group has attracted attention for threatening disclosure rather than deploying file-encrypting ransomware, and Security Affairs and SC World both describe an operation targeting organizations in the United States, United Kingdom, Sweden, and elsewhere.

The immediate problem is that ExfilSquad’s public narrative is running ahead of the evidence. SOCradar, which profiled the group shortly after it surfaced in late July, said it had found no forensic evidence, independently verifiable samples, confirmed intrusion path, malware, or reliable technical indicators tying ExfilSquad to most of the organizations named on its leak site. It specifically warned that some listings may involve reused or fabricated data.

That distinction is no longer academic. The Police National Legal Database has confirmed that data taken in a cyberattack was published online, and IT Pro and TechRadar reported that the exposed material affected more than 100,000 police and criminal-justice personnel. That makes the PNLD incident a confirmed data-exposure event; it does not validate every other name ExfilSquad has placed beside it.

A dark cybercrime control room depicts hackers, phishing emails, stolen identities, and global network surveillance.The claimed 13 targets do not match the first public listing​

The supplied reporting says ExfilSquad announced 13 new victim organizations. Public leak-site tracking tells a more complicated story. RansomLook recorded a burst of 15 ExfilSquad posts on July 26, 2026, appearing within minutes of one another: Microsoft, Allstate, Frontier Airlines, Analog Devices, Viavi Solutions, Newcastle University, the City of Atlanta, the City of Houston, the UK Department for Education, the Police National Legal Database, and several others.

SOCradar independently documented the same initial set of 15 claims. Its assessment is important because it found the claims arrived as a concentrated launch-day publication burst, rather than as disclosures following separately documented intrusions. The firm said no samples or external confirmations accompanied the bulk of those listings.

That means the public record currently supports two separate facts. ExfilSquad has named a substantial number of organizations and is operating an extortion-oriented leak site. The public record does not yet establish that all named organizations suffered distinct, recent breaches by the same actor.

The purported new batch of 13 needs the same scrutiny. No public evidence located for this report independently establishes the full identity of those 13 organizations, their compromise dates, the affected systems, the volume or type of data taken, or whether any victims were notified before the claims were posted. Those gaps should control how security teams interpret the story.

For customers, partners, and employees of a named company, the sensible response is heightened phishing awareness and vigilance around impersonation—not an assumption that passwords, payment data, or production systems have necessarily been compromised.


Torrent publication changes the cleanup problem​

A conventional extortion group can keep stolen material on a dark-web portal, a cloud-storage account, or a single file-hosting service. Those locations can be reported, blocked, or removed—sometimes slowly, but through a finite set of operators. BitTorrent works differently: a file is broken into pieces and distributed among peers, with participants able to continue sharing pieces they have obtained.

RansomLook’s torrent-health tracker includes ExfilSquad among the groups for which it monitors magnet-linked posts. That is evidence that torrent distribution is part of the operation’s observed publication infrastructure, although it does not establish the authenticity of every file or claim associated with the group.

For victims, the practical consequence is severe. Once a leak becomes a functioning swarm with multiple seeders, removing the original host does not necessarily make the data unavailable. New copies can be created rapidly, repackaged, renamed, moved to other forums, or used as bait in phishing campaigns. A torrent can also turn an extortion event into a longer-lived exposure-management problem: even after an organization contains the intrusion, it may still have to monitor reappearances and downstream abuse of the data.

This is why the term data leak can understate the operational impact. The first task is still to determine whether a breach occurred and stop any ongoing access. But if files have already been published through peer-to-peer channels, response teams also need a plan for credential resets, targeted anti-phishing messaging, fraud monitoring, legal notification analysis, and external monitoring for renamed archives and republished datasets.

The group’s model is financially familiar even without encryption. It creates pressure by naming organizations, attaching alleged data descriptions and deadlines, and making the reputational cost of nonpayment appear immediate. Torrent distribution makes that pressure more credible where the files are genuine.

The Microsoft Dataverse allegation is unproven—and still useful as an audit prompt​

The report says ExfilSquad has exploited cloud portals, including misconfigured Microsoft Dataverse, Power Pages, and customer relationship management systems. At present, there is no public technical evidence connecting ExfilSquad to a specific Dataverse flaw, Power Pages exploit, exposed tenant, or configuration error. SOCradar’s review reached the same conclusion more broadly: no confirmed ExfilSquad initial-access technique or toolset is publicly available.

Administrators should resist an easy but dangerous leap from “Dataverse was mentioned” to “a Microsoft platform vulnerability was exploited.” There is no basis in the available reporting to make that attribution.

Still, the allegation highlights a real Power Platform governance issue. Microsoft’s documentation makes clear that Power Pages user access to Dataverse data is mediated through web roles and table permissions. It also warns that assigning a table permission to the Anonymous users web role can make the table’s data available to anyone visiting the site. Power Pages also supports column permissions, which can restrict access to sensitive fields even where access to a record is necessary.

In other words, the useful defensive lesson is configuration review, not emergency patching for an unverified actor-specific exploit.

Organizations running external Power Pages sites should check for the following immediately:

  • Review every table permission assigned to Anonymous users and remove public access that is not essential to the site’s stated function.
  • Confirm that public forms, lists, Liquid templates, and Portals Web API calls expose only the records and columns required for the user journey.
  • Review parent-child table permissions and web-role inheritance, because an apparently narrow permission can become broader through relationships and assigned roles.
  • Verify that private-site settings, identity-provider configuration, and Microsoft Entra administrative roles still match the intended audience for the portal.
  • Search Dataverse, Power Platform, identity-provider, proxy, and endpoint logs for unusual high-volume queries, bulk exports, repeated failed authorization checks, archive creation, and outbound data transfers.

This work should be prioritized for environments that store customer service interactions, case records, employee information, school or government data, or business contacts. It is also a good time to confirm that sensitive fields are excluded from public-facing views by default rather than hidden only through front-end design choices.


Confirmed breaches must not become cover for unverified claims​

The PNLD incident shows why ExfilSquad cannot simply be dismissed as a fake-name operation. There is a material difference between a criminal group making an unsupported listing and a victim organization confirming that a data breach occurred and data was published. The latter has happened.

But confirmation in one case is not transferable proof. ExfilSquad’s original July 26 leak-site burst included Microsoft among its claimed targets, yet SOCradar said the claim set lacked independent validation, and no public technical evidence has emerged establishing a compromise of Microsoft systems by the group. The same disciplined standard should apply to all the newly reported organizations.

This matters most for IT teams because threat-actor claims can generate secondary harm before a breach is verified. Criminals and opportunistic scammers can use a company’s appearance on a leak site as a pretext for credential-harvesting emails, fake data-removal services, bogus incident-response offers, fraudulent invoice changes, or demands supposedly sent by the victim’s legal department.

Security and communications teams should prepare a short, accurate holding statement before one is needed: the organization is aware of the claim, is investigating, and will communicate confirmed facts to affected parties. They should avoid declaring either that an intrusion definitely occurred or that it definitely did not until identity, cloud, endpoint, and data-access logs have been reviewed.

The response clock starts before attribution is complete​

ExfilSquad’s significance is less about a novel malware family than about the combination of mass victim claims, public data-extortion deadlines, and distribution channels that can keep a leak alive after a single website disappears. The operation may prove to be a serious and active data-theft group, a mix of genuine intrusions and recycled material, or an actor exaggerating its access. The available evidence does not yet settle that question.

What is established is narrower and more actionable: a confirmed PNLD data exposure has been linked in reporting to ExfilSquad’s publication activity, while most of the group’s broader claims remain unverified. Organizations named by the group should investigate their own telemetry now, and Power Platform administrators should audit external Dataverse exposure before a threat actor’s unsupported allegation becomes the first warning that a public portal was configured too broadly.