ExfilSquad leaks data via torrents

Can you imagine your corporate data circulating across the internet with nothing you can do about it?
ExfilSquad has just added thirteen new victims to its extortion list.
This group does not use ransomware: it silently steals information and threatens to publish it unless you pay. No file encryption, no visible alarms.
The deadline is August 5, 2026. If organizations fail to negotiate in time, their data will be exposed with no way back.

Thirteen organizations fell into the crosshairs simultaneously.
The victims are spread across the United States, the United Kingdom, and Sweden, and in July the group had already attacked a major financial institution in Nigeria. ExfilSquad gained access by exploiting misconfigured cloud portals and SaaS platforms: Microsoft Dataverse environments, Power Pages sites, and customer management systems. No sophisticated exploit is needed when the door is already ajar.
What comes next makes the damage unstoppable.
Once they have the data, ExfilSquad distributes it via torrents: each victim is assigned a unique tracker and an initial seed. The stolen information spreads across decentralized P2P networks and anyone can download it: other malicious actors, competitors, anyone. Resecurity detected that the most active nodes on August 7 originated from China and Russia, pointing to prior coordination.
Once published on torrents, no one in the world can erase it.
The decentralized nature of P2P turns every leak into something permanent. Other participants resume the download as soon as anyone tries to stop it. The reputational and financial damage to affected companies only grows over time, because the data does not disappear: it multiplies.

This method is not exclusive to ExfilSquad.
LockBit 3.0 and Cl0p have already used torrents to distribute stolen data. The tactic is becoming established among sophisticated hack-and-leak groups.
The decentralization of P2P makes it impossible to remove files once they have been seeded into the network.
ExfilSquad exposed data on more than 100,000 law enforcement officers and justice professionals in its attack on the UK police database.
Digital extortion now has an expiration date.
The August 5 deadline forces organizations to choose between paying or accepting that their information will live forever on networks no one controls. That decision carries consequences that go far beyond money.
Real people are the ones most overlooked.
When ExfilSquad attacked the UK National Police legal database, the victims were not just institutions: they were more than 100,000 individuals with their names, surnames, and contact details exposed. Active officers, prosecutors, justice system workers. People whose personal safety depends directly on that information not falling into the wrong hands. And it already has.
Resecurity has been tracking every move of the group in detail for months.
The firm detected ExfilSquad’s activity since its emergence in mid-2026 and analyzed the torrent distribution nodes. Its conclusions are clear: this tactic is not improvised. It is a trend among sophisticated actors who have understood that leaking data in a decentralized manner multiplies the impact without increasing their own operational risk.

China and Russia led the active distribution of the leaked data.
The most active servers on the torrent network on the day of publication originated from both countries. This may indicate prior knowledge of the leak or simply a particular interest in that type of data. Either way, the information is already traveling without a passport.
The business model has evolved without ransomware.
ExfilSquad demonstrates that there is no need to encrypt anything to extort effectively. All it takes is stealing, threatening, and publishing. And if the victim does not pay, the leak becomes free publicity for the group: it proves they follow through on their threats, making the next ones more credible. It is a self-reinforcing cycle.
Corporate silence also carries a real cost.
Every organization that does not publicly confirm the incident leaves its users without the information they need to protect themselves. Meanwhile, the data keeps circulating.
Protect your organization
- ✓Audit the configuration of your cloud and SaaS environments right now.
- ✓Enable anomalous access alerts in your CRM systems.
- ✓Prepare a response protocol for data extortion.
Is your company ready to negotiate against the clock?
Security is not improvised, it is audited. At Nacata Security we detect vulnerabilities and protect your company, because a single flaw can cost you everything you have built.
Related articles
Nacata Security, reach out to us anytime
We are Nacata Security, get to know us
web: nacata.io
email: info@nacata.io
Phone: 919930793
LinkedIn: Nacata Security
Cyberattacks that have already happened and are confirmed: hacked companies, leaked data, services down after an attack, ransoms paid.
Real cases, with names and clear consequences, explained simply so anyone understands what happened and who it affected.
RATING
8.6
Who are we?
At Nacata Security we are an offensive cybersecurity company specialized in audits and penetration testing.
We detect, assess and help mitigate the vulnerabilities of your systems, networks and applications before a real attacker exploits them, offering 360º defense tailored to each client.
We’d be glad to get in touch with you for whatever you need.




