
At CYFIRMA, we continuously monitor emerging cyber threats affecting organizations across critical sectors worldwide. On July 26, 2026, the newly emerged ransomware group ExfilSquad listed Microsoft on its dark web leak site, claiming to have compromised the company and exfiltrated approximately 130 GB of uncompressed data containing nearly 8 million records.
The group has set a negotiation deadline of August 5, 2026, urging Microsoft to make contact or risk public release of the alleged data.
This assessment is based on currently available intelligence as of July 27, 2026. At the time of writing, CYFIRMA has not identified any evidence confirming the authenticity of ExfilSquad’s claims, and Microsoft has not issued any public statement or breach notification regarding the alleged incident. Consequently, the reported compromise remains unverified. This assessment may change if ExfilSquad releases verifiable proof of compromise or Microsoft issues an official statement. CYFIRMA will continue monitoring the threat actor’s activity and provide timely updates as new intelligence becomes available.
CYFIRMA has identified a newly emerged ransomware group named ExfilSquad, which claims to have exfiltrated Microsoft data. According to the threat actor, the alleged dataset contains approximately 8 million records, including personally identifiable information (PII), employee and customer contact details, authentication data, password hashes, portal identities, corporate account information, business leads, facilities management records, internal service tickets, and access permissions.

At the time of writing, these claims remain unverified, and no independent evidence has been identified to confirm that Microsoft has been compromised or that the purported data has been exfiltrated.
If validated, this could lead to potential credential exposure, identity theft risks, and reputational impact. However, the claimed data volume of 130 GB appears unusually modest for an organization the size of Microsoft, which raises significant doubts. CYFIRMA continues to monitor this ransomware incident closely for any escalation or release of proof packages that could affect Microsoft customers and partners.
CYFIRMA Observation:
ExfilSquad appears to be in an aggressive initial campaign phase aimed at building notoriety. We are actively profiling the group’s infrastructure and TTPs.
ExfilSquad’s claim against Microsoft has attracted significant attention due to Microsoft’s global presence and the volume of data allegedly compromised. At present, however, there is no independently verified evidence confirming the authenticity of the threat actor’s claims, and Microsoft has not issued any official statement regarding the alleged incident.
CYFIRMA will continue monitoring ExfilSquad’s leak site, dark web activity, and other intelligence sources for proof-of-compromise, leaked datasets, or official updates. Any newly validated intelligence will be assessed and shared with clients to support informed risk assessments and timely defensive actions.
Immediate (0–48 Hours):
Short-term Mitigation:
CYFIRMA Support: