#exfilsquad
Welsh police force went dark on email and public contact for days before saying a word about it. https://intel.threadlinqs.com/threat/TL-2026-2694 #ThreatIntel #ExfilSquad #Police #Cyberattack
September 27, 2026 at 11:34 AM
UK Cybercrime Journal: ExfilSquad Emerges
UK Cybercrime Journal: ExfilSquad Emerges
blog.bushidotoken.net
September 5, 2026 at 2:54 PM
Also see ExfilSquad, for example.
September 3, 2026 at 7:09 AM
New Blog! 🇬🇧 UK Cybercrime Journal: ExfilSquad Emerges

- ExfilSquad’s extortion campaign targets UK public sector orgs, education, and law enforcement
- ExfilSquad's primary attack vector involves exploiting CRM platforms and Microsoft Power Pages

🔗 blog.bushidotoken.net/2026/09/uk-c...
UK Cybercrime Journal: ExfilSquad Emerges
CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security
blog.bushidotoken.net
September 3, 2026 at 5:35 AM
New Blog! 🇬🇧 UK Cybercrime Journal: ExfilSquad Emerges

- ExfilSquad’s extortion campaign targets UK public sector orgs, education, and law enforcement
- ExfilSquad's primary attack vector involves exploiting CRM platfor…

— from @BushidoToken (https://x.com/BushidoToken/status/2095384710214017262)
September 3, 2026 at 5:51 AM
30 days after ExfilSquad published they harvested data from orgs using Power Pages, sites like ATL311 remain online. Showing PII data via publicly visible case detail records that contain customer names, email threads etc.

Built by Accenture, designed by no one.🙄

www.linkedin.com/feed/update/...
August 25, 2026 at 12:06 PM
Extortion group ExfilSquad claims to have stolen over 27 million records from 13 organizations including governments and airlines through publicly accessible Microsoft Power Pages portals.

#CloudSecurity #DataBreach #Dataverse #Dynamics365 #Enterprise #Exfilsquad #Microsoft #PowerPages
27M Records Exposed Via Misconfigured Microsoft Power Pages
Extortion group ExfilSquad claims to have stolen over 27 million records from 13 organizations including governments and airlines through publicly accessible Microsoft Power Pages portals.
pulseofnations.lol
August 21, 2026 at 2:09 PM
📢 ExfilSquad : nouveau groupe d'extorsion cible des données Microsoft D365 via Power Pages mal configurés

Cet article analyse l'activité du groupe d'extorsion ExfilSquad, apparu le 26 juillet 2026 sur le dark web avec des…

🟢 vérification factuelle haute
#D365 #ExfilSquad #Cyberveille
ExfilSquad : nouveau groupe d'extorsion cible des données Microsoft D365 via Power Pages mal configurés
Cet article analyse l'activité du groupe d'extorsion ExfilSquad, apparu le 26 juillet 2026 sur le dark web avec des revendications de compromission de 15 organisations. ExfilSquad est un groupe d'extorsion de données émergent qui a publié un site de fuite sur Tor le 26 juillet 2026.
cyberveille.ch
August 18, 2026 at 2:00 PM
ExfilSquad: New Data Extortion Group Leaks Microsoft D365 Data, Likely Linked to Misconfigured Power Pages https://packetstorm.news/news/view/42805 #news
August 17, 2026 at 7:51 PM
-Bank hackers arrested in Brazil and EU
-PXA Stealer admin arrested in Vietnam in March
-NC man sentenced for extortion
-ExfilSquad likely hacked Microsoft D365 servers
-Dysphoria botnet reaches 300k
-New Majinahanashi ransomware
-CRPx0 launches leak site
-HoneyMyte updates CoolClient backdoor
August 17, 2026 at 1:19 PM
ExfilSquad: New Data Extortion Group Leaks Microsoft D365 Data, Likely Linked to Misconfigured Power Pages
ExfilSquad: New Data Extortion Group Leaks Microsoft D365 Data, Likely Linked to Misconfigured Power Pages
www.fortra.com
August 17, 2026 at 9:54 AM
Microsoft Power Pagesの設定ミス、ExfilSquadに2,700万件の記録が流出した可能性

Microsoft Power Pagesの設定不備とみられる問題により、13の組織にまたがる約2,700万件の記録が流出した可能性があることがわかりました。データ恐喝グループのExfilSquadが、被害者データとされる382.64GB分をトレント配信で公開したことで判明したものです。GetDatabase Too...
Microsoft Power Pagesの設定ミス、ExfilSquadに2,700万件の記録が流出した可能性
Microsoft Power Pagesの設定不備とみられる問題により、13の組織にまたがる約2,700万件の記録が流出した可能性があることがわかりました。データ恐喝グループのExfilSquadが、被害者データとされる382.64GB分をトレント配信で公開したことで判明したものです。GetDatabase Too
blackhatnews.tokyo
August 17, 2026 at 9:42 AM
ExfilSquadのハッカー集団、Microsoft D365のデータ382GBを13の被害組織から流出

ExfilSquadと名乗る新たなデータ恐喝グループが、Microsoft Dynamics 365のCRMおよびERP環境から窃取したとされる382.64GBのデータを、13の組織から流出させたと主張しています。 流出したアーカイブには約2,700万件のレコードが含まれているとされ、個人を特定できる情報、カスタマー...
ExfilSquadのハッカー集団、Microsoft D365のデータ382GBを13の被害組織から流出
ExfilSquadと名乗る新たなデータ恐喝グループが、Microsoft Dynamics 365のCRMおよびERP環境から窃取したとされる382.64GBのデータを、13の組織から流出させたと主張しています。 流出したアーカイブには約2,700万件のレコードが含まれているとされ、個人を特定できる情報、カスタマー
blackhatnews.tokyo
August 17, 2026 at 6:52 AM
Researchers Confirm ExfilSquad’s Access to Sensitive Data Across 13 Organizations - www.infosecurity-magazine.com/news/exfilsq...
Researchers Confirm ExfilSquad’s Access to Sensitive Data
Researchers have verified that ExfilSquad possesses sensitive data stolen from at least 13 victims after the extortion group published leaked datasets via torrents
www.infosecurity-magazine.com
August 17, 2026 at 2:36 AM
Supply chain giant Wesco confirms a security incident after extortion group ExfilSquad claims theft of 2.6M records from a cloud CRM. The data was leaked after ransom was not paid. Misconfigured Microsoft Power Pages is the suspected vector. #DataBre...

🌐 cyber[.]netsecops[.]io
Wesco Probes Cloud CRM Breach Claimed by
Wesco is investigating a cloud CRM data breach after the ExfilSquad extortion group claimed to have stolen 2.6 million records and leaked the data online.
cyber.netsecops.io
August 16, 2026 at 3:10 PM
Hackers expose details of 100k police staff on dark web www.thecanary.co/uk/2026/08/0... This is a weird one why would 100,000 police staff be trolling around on the dark web? Anyone provide any insights?
Hackers expose details of 100k police staff on dark web
Hackers ExfilSquad put more staff in danger – this time police officers and staff whose names and contact details were leaked on the dark web
www.thecanary.co
August 15, 2026 at 2:06 PM
ExfilSquad verified extortion claims against fifteen organisations thanks to open Microsoft Power Page portals. Why do we even bother setting permissions?

#SameOldStory #ITFailures
August 15, 2026 at 6:34 AM
Researchers confirm data extortion group ExfilSquad has leaked 382 GB of sensitive data from 13 organizations, including government and education sectors. The attack is believed to be linked t...

https://verisizintisi.com/en/blog/2026-08-15-exfilsquad-leaks-sensitive-data-from-13-organizations
August 15, 2026 at 12:02 AM
ExfilSquad’s Data Extortion Campaign Exposes a Dangerous Microsoft Power Pages Weakness

Introduction: When a Public Portal Becomes a Data Breach A new cyber-extortion operation has moved from making alarming claims to demonstrating that at least some of those claims are backed by real stolen…
ExfilSquad’s Data Extortion Campaign Exposes a Dangerous Microsoft Power Pages Weakness
Introduction: When a Public Portal Becomes a Data Breach A new cyber-extortion operation has moved from making alarming claims to demonstrating that at least some of those claims are backed by real stolen information. ExfilSquad, a newly emerged data-extortion group, has published large collections of allegedly stolen data connected to organizations in government, education, financial services, transportation, manufacturing and other industries.
undercodenews.com
August 14, 2026 at 3:08 PM
研究者、ExfilSquadが13組織の機密データにアクセスした事実を確認

データ恐喝グループ「ExfilSquad」に関する新たな分析により、同グループが政府、教育、金融サービス、製造業などの分野に属する少なくとも13組織から流出させたデータとの関連が明らかになりました。 Fortra Intelligence and Research Experts(FIRE)は、同グループが公開...
研究者、ExfilSquadが13組織の機密データにアクセスした事実を確認
データ恐喝グループ「ExfilSquad」に関する新たな分析により、同グループが政府、教育、金融サービス、製造業などの分野に属する少なくとも13組織から流出させたデータとの関連が明らかになりました。 Fortra Intelligence and Research Experts(FIRE)は、同グループが公開
blackhatnews.tokyo
August 14, 2026 at 3:02 PM
⚠️ Wesco confirms breach after ExfilSquad claim

#Wesco disclosed a security incident after the group claimed data theft.
🔗 read more: www.bleepingcomputer...

#ransomNews #cybersecurity
Wesco confirms security incident after ExfilSquad claims data theft
Global supply chain and distribution giant Wesco has confirmed in a statement for BleepingComputer that it is investigating a cybersecurity incident.
www.bleepingcomputer.com
August 14, 2026 at 1:37 PM