EXFILSQUAD , a new cybercrime group that emerged in mid-2026, is targeting organizations by stealing data and threatening to leak it unless a ransom is paid. They focus on exploiting cloud tools like Microsoft Dataverse and CRM systems, recently attacking 13 organizations across the U.S., UK, and Sweden, with a notable previous attack on a Nigerian financial institution. The group utilizes torrents to distribute stolen data, making it widely available and complicating efforts to halt its circulation.
Resecurity indicates that this tactic is part of a growing trend among sophisticated hackers engaging in 'hack-and-leak' operations, with significant distribution activity linked to hosts in China and Russia.