ExfilSquad
Intelligence Profile
Only exfiltration
Intelligence Assessment
ExfilSquad is a financially motivated ransomware operation that focuses exclusively on data exfiltration. The group operates as a threat actor targeting various global sectors.
They have claimed 20 victims in the last 90 days, spanning sectors such as Government, Technology, and Education, with a presence in the US, UK, Nigeria, and Sweden.
The actor is currently active, having conducted attacks as recently as July 26, 2026.
Threat Analysis
ExfilSquad is a ransomware operation that deploys encryption-based extortion against organizations globally. This group maintains a data leak site (DLS) to pressure victims into paying ransom demands.
Financially motivated threat actors like ExfilSquad prioritize monetary gain through methods such as ransomware deployment, banking trojans, cryptocurrency theft, BEC scams, or credential harvesting for resale on underground markets.
Ransomware Victims (20)
CTIWATCH tracks 20 organizations claimed as victims by ExfilSquad on its data leak site, with attack dates, sectors and countries.
View full victims list →Known Campaigns
ExfilSquad is conducting an active ransomware campaign targeting organizations across 4 countries. Primary targets: Education, Financial Services, Government & Defense. 20 confirmed victims recorded in the last 45 days. Campaign status: ACTIVE (last activity 26 Jul 2026).