Tech News

ExfilSquad Targets Microsoft, Claims 8 Million Records With Little Evidence

8 million records, 130 GB of uncompressed data, and a deadline set for August 5, 2026. That’s what the ExfilSquad group claims to have on Microsoft. But take it with a grain of salt: this cybercriminal group seemingly came out of nowhere and appeared on July 26. Since then, it has published around fifteen claims in a single day, and above all, there is very little evidence... Here’s what we know.

Fifteen claims in one day, with no evidence to back them up

A new data breach at Microsoft? Not so fast. Nothing is confirmed, and caution is absolutely warranted. That said, it is worth discussing, or rather, worth discussing ExfilSquad. In fact, the ExfilSquad gang appeared publicly on July 26, 2026, with a Tor-hosted site used to list its victims. Nothing unusual there.

What is less ordinary is the barrage of victims announced that same day. The group posted all of its claims at once, totaling fifteen organizations, and the list includes some heavy hitters: Wesco International, Analog Devices, Bonava, the cities of Atlanta and Houston, Viavi Solutions, the University of Newcastle, the District of Columbia Public Schools, Zenith Bank, Frontier Airlines, TaylorMade, Allstate, the UK National Legal Database Police, the United Kingdom Department for Education, and... Microsoft. No less.

The entry dedicated to Microsoft follows a standardized format: country, estimated revenue of $318 billion, a claimed volume of 130 GB of uncompressed data, and an ultimatum set for August 5, 2026. ExfilSquad claims to have stolen the following information:

  • Large volumes of personal information
  • Employee and customer contact details
  • Authentication data and password hashes
  • Portal identities and enterprise account information
  • Facility management records and internal service tickets
  • Access rights

In total, there would be 8 million records. Except, there is no proof. No screenshot, no file listing, and no details accompanied those initial posts. The SOCRadar report even raises two possibilities: the data could be recycled or entirely fabricated. And above all, we know almost nothing about this group.

A sample that appears to point to a partner portal

As SOCRadar explains, the only potentially credible lead is an X post published by the @exfilsquad account. The post dates from July 27, 2026, and mentions a Microsoft account, along with a screenshot. Based on what can be seen in that image, it looks like an export from a directory record. "Its authenticity has not been confirmed," SOCRadar notes.

Source: SOCRadar

Several analyses, including SOCRadar’s, point to a possible link with Dynamics 365 and Power Platform. If the sample turns out to be authentic, it is possible that a partner portal was affected rather than Microsoft’s production systems.

For now, the mystery remains unsolved. Microsoft has not issued any statement on the matter. If this story gains traction, the Redmond company should speak out quickly, whether to deny or confirm a data breach. Otherwise, we’ll have to wait until August 5 to learn more... We’ll then know whether this was a publicity stunt or a real data breach.

author avatar
Florian Burnel Co-founder of IT-Connect
Systems and network engineer, co-founder of IT-Connect and Microsoft MVP "Cloud and Datacenter Management". I'd like to share my experience and discoveries through my articles. I'm a generalist with a particular interest in Microsoft solutions and scripting. Enjoy your reading.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.