HomeMalware & ThreatsExfiltration-Focused ExfilSquad Begins Releasing Stolen Data

Exfiltration-Focused ExfilSquad Begins Releasing Stolen Data

Published on

spot_img

Cities of Atlanta and Houston, and Frontier Airlines, Among New Group’s Victims

A newly emerged cybercrime group, known as ExfilSquad, has become infamous for its focus on data theft and extortion. The group made headlines when it launched its data-leak website late last month, showcasing sensitive information including stolen data related to British police officers. ExfilSquad’s claims have also extended to records taken from the U.K. Department of Education, showcasing its broad target audience. On July 26, within just a day, the group professed to have successfully hacked 15 organizations, notably including the municipal governments of both Atlanta and Houston.

As news of the attacks spread, ExfilSquad escalated its operations by sharing links to torrent files that allegedly contained complete copies of all stolen data, clearly demonstrating their intent to pressure victims into making payments. The tactics used by ExfilSquad mirror those of other extortion-focused cybercrime entities. They psychologically manipulate victims by stating, "Once your company’s data is posted here, it’s NEVER leaving the public eye and it will be passed around the internet FOREVER. The payment we request of you is simply a rounding error compared to the litigation costs of your data leaking. Be smart and just pay." Such messages serve to instill fear and urgency, compelling organizations to consider paying the ransom.

The group’s list of victims also includes well-known entities such as Allstate, District of Columbia Public Schools, and Wesco International, a supply chain leader based in Pittsburgh. In a notable incident involving the D.C. Public Schools system, the group chose not to leak children’s data, opting instead to release only sanitized records. Cybersecurity firm Resecurity highlighted this decision, indicating a curious ethical boundary maintained by the criminals.

Another significant breach was reported by Newcastle University, where ExfilSquad claimed to have stolen 440,000 records containing personal identifiable information (PII) of applicants and students. The university confirmed this on July 27, after being alerted by an external party. Their investigation revealed a configuration error in one of their admissions systems, which allowed unauthorized access to contact information, but crucially did not include admissions-related data or exam results.

As investigations into these breaches continued, experts noted that ExfilSquad primarily appears to target customer relationship management (CRM) systems and internal case management systems. Resecurity observed that several victims mentioned compromised CRM metadata, indicating significant risks pertaining to customer PII.

In recent developments, ExfilSquad recently removed Zenith Bank of Nigeria from its list of victims on the data-leak site. Zenith Bank, one of Nigeria’s largest financial institutions, had warned its customers earlier regarding unauthorized access to their data, prompting concerns about the potential fallout from the breach. Cybersecurity experts have suggested that removal from such lists often indicates that a victim has either paid a ransom or is negotiating with the attackers.

Adding to the complexity of the situation, data exfiltration trends indicate a decline in the number of ransomware victims who choose to pay ransom demands, especially for attacks that consist solely of data theft. A report from Coveware, a ransomware response firm, revealed that only 15% of victims opted to pay after a theft—an all-time low compared to previous quarters. Industry leaders and cybersecurity experts caution against paying ransoms as it might validate the attackers’ claims and reinforce their tactics.

One notable target in ExfilSquad’s campaign is Frontier Airlines, an ultra-low-cost carrier operating out of Denver. The group alleges that they obtained 43 gigabytes of data, equating to approximately 2.4 million records, which include sensitive personal information, customer support cases, and travel documents. Uncertainty remains around whether ExfilSquad was the sole perpetrator of the breach, especially since vulnerabilities in the airline’s systems had already been reported by ethical hackers prior to the attacks.

In mid-July, Frontier Airlines began notifying relevant authorities and impacted customers about a breach linked to an incident in mid-June, revealing that sensitive data such as Social Security numbers, passport details, and dates of birth had been exposed.

Complicating matters further, a lawsuit filed in federal court and seeking class-action status claims that the attack was orchestrated by a collaborative group of cybercriminals, known as Scattered Lapsus$ Hunters. Intricacies in the cyber landscape emerged as members of other groups, such as ShinyHunters, clarified through reports that they had no association with the Frontier hack.

ExfilSquad maintains that they are an entirely separate entity, refuting any links with ShinyHunters. They emphasized that the current breaches listed are the result of misconfigurations in certain Microsoft tools, and they underscored that they exploited these weaknesses to extract customer data from Frontier’s systems.

Experts continue to analyze the affiliations and motivations behind ExfilSquad, with some pondering if they are part of a broader trend related to the evolving landscape of cybercrime. Notably, the group has been observed using the image of a cybersecurity researcher, Allison Nixon, which raises questions about their connections to particular cybercriminal communities. Nixon, who frequently exposes these individuals, expressed skepticism towards any potential victims who might consider cooperating with ExfilSquad, highlighting that members of such communities often fracture trust.

In conclusion, as ExfilSquad’s operations unfold, it raises profound concerns around cybersecurity, particularly the vulnerability of sensitive data and the dangerous methods employed by cybercriminals. With organizations scrambling to protect their data and restore their reputations, the ongoing challenges illustrate the critical need for robust cybersecurity measures in an increasingly digital landscape.

Source link

Latest articles

Margarita Howard’s HX5 Implements CMMC Compliance Ahead of AI Regulations

Margarita Howard: A Pioneer in the Evolving Landscape of Government Contracting Margarita Howard has dedicated...

Court Establishes Stringent Security Measures for Change Health’s Stolen Data

Strict Security Protocols Established for Handling Stolen Data in Change Healthcare Cyberattack A recent court...

WordPress Plugins Compromised Without Any File Modifications

Rogue Administrator Accounts and Webshells Planted Through WordPress Plugins In a significant security breach, seven...

Cyber Briefing – August 10, 2026 – CyberMaterial

Cybersecurity Briefing: Key Developments and Threats Cybersecurity is increasingly becoming a focal point for businesses...

More like this

Margarita Howard’s HX5 Implements CMMC Compliance Ahead of AI Regulations

Margarita Howard: A Pioneer in the Evolving Landscape of Government Contracting Margarita Howard has dedicated...

Court Establishes Stringent Security Measures for Change Health’s Stolen Data

Strict Security Protocols Established for Handling Stolen Data in Change Healthcare Cyberattack A recent court...

WordPress Plugins Compromised Without Any File Modifications

Rogue Administrator Accounts and Webshells Planted Through WordPress Plugins In a significant security breach, seven...