Back to news
Cybersecurity Alert
August 2, 2026 by EmailMeNow IT Consulting

ExfilSquad Named 14 Victims in One Day — Claims Unverified; We Audited the Domains

ExfilSquad posted ~14 high-profile victims on July 26, 2026 — including Microsoft (~8M), Zenith Bank (~90M), and City of Houston (~6M). Researchers call evidence thin. Domain audits (ideal 100%): none at 100%; flyfrontier.com 74%; dcps.dc.gov 30%.

Source: GalaxyWarden · RuntimeWire · SOCRadar (via reporting)

NewsRansomwareData BreachExfilSquadTexasLocal GovernmentMFACybersecurity
Unverified ransomware leak-site dashboard naming many victims at once

ExfilSquad appeared on July 26, 2026 with a Tor leak site and a simultaneous dump of roughly 14–15 victim names — Microsoft, Zenith Bank, the cities of Houston and Atlanta, Frontier Airlines, and more — claiming a combined volume over 115 million records. Independent trackers such as GalaxyWarden documented the listings; researchers and reporters (including RuntimeWire and IT-Connect) stress that public evidence remains thin and that fabrication or recycled data is currently more plausible than fourteen verified megabreaches on one day.

This is not a confirmed multi-org breach roundup. It is a leak-site claim campaign that still drives phishing risk — especially for Houston residents and Frontier customers who already see real-world scams after any municipal or airline headline.

We audited each named organization’s primary public domain against the 100% ideal, probed website stacks, checked lookalike domains, and reviewed MFA docs (YubiKey / Google Authenticator) for the highest-visibility names.

Illustration: flashy leak-site claims versus empty forensic evidence tray

Why skepticism is warranted

SignalWhat researchers note
TimingMany listings posted seconds apart on launch day (RansomLook timing cited by RuntimeWire)
ProofLittle/no authenticated sample sets tying dumps to production systems
Microsoft claim~8M records / 130 GB / Aug 5 deadline — sample authenticity not confirmed (SOCRadar via IT-Connect)
Actor historyNew public footprint; classified more as exfiltration/extortion branding than a proven encryptor family
Scale disparityClaims range from ~90M (Zenith) to ~135K (PNLD) announced together

Treat every row below as an attacker assertion until the named org confirms, regulators file, or authenticated samples are validated.

Alleged victims (attacker claims)

Volumes and data types below follow the public ExfilSquad / GalaxyWarden-style summaries circulating after July 26, 2026. They are not EmailMeNow confirmations.

OrganizationSectorClaimed volumeDomain
MicrosoftTechnology (USA)~8Mmicrosoft.com
Zenith Bank PlcBanking (Nigeria)~90Mzenithbank.com
City of HoustonLocal government~6Mhoustontx.gov
City of AtlantaLocal government~3Matlantaga.gov
Frontier AirlinesAirline~2.4Mflyfrontier.com
TaylorMade / Sun Day RedGolf equipment~2Mtaylormade.com
AllstateInsurance~657Kallstate.com
BonavaReal estate (Nordics)~842Kbonava.com
Analog DevicesSemiconductor~570Kanalog.com
Newcastle UniversityHigher ed (UK)~440Kncl.ac.uk
Viavi SolutionsTest & measurement~430Kviavisolutions.com
Police National Legal DatabaseUK justice data~135Kpnld.co.uk
UK Dept for EducationUK government~600Keducation.gov.uk
DC Public SchoolsK–12 (Washington, DC)Unspecifieddcps.dc.gov

Claimed data themes (by listing): PII and contacts; banking/account fields (Zenith); municipal service tickets (Houston/Atlanta); airline support/travel cases (Frontier); orders/shipping (TaylorMade); HR/recruiting (Allstate); property/warranty (Bonava); applicant/student contacts (Newcastle); enterprise IDs (Viavi); force-area contacts (PNLD); parent/staff help-portal entries (DfE).

Some feeds also list Wesco International (~2.6M) in the same launch wave (GalaxyWarden) — outside the 14-name table above.

Texas angle — City of Houston & Frontier

GalaxyWarden’s Houston write-up restates the listing’s ~6M municipal CRM / service-request narrative (contacts, addresses, complaint text). That material — if real — would fuel highly convincing “311 / utility / citation” phishing. Separately, Frontier already faces a documented 2026 incident and lawsuits tied to Scattered Lapsus$ Hunters, not ExfilSquad (our Frontier coverage). ExfilSquad’s ~2.4M Frontier claim should not be conflated with that confirmed case.

Illustration: Houston skyline under spoofed municipal notice phishing after leak-site claim

Independent cybersecurity audits

EmailMeNow audits on August 2, 2026. 100% is the ideal overall score — 0 of 14 reached it. Scores measure public identity / transport / website posture, not whether ExfilSquad’s dump is real.

OrganizationDomainOverallIdentityTransportWebsite
Bonavabonava.com76%70%15%92%
Frontier Airlinesflyfrontier.com74%65%15%92%
Viavi Solutionsviavisolutions.com70%75%15%65%
Microsoftmicrosoft.com68%90%70%45%
Analog Devicesanalog.com63%75%15%40%
Newcastle Universityncl.ac.uk61%65%70%37%
Allstateallstate.com60%65%40%40%
Zenith Bankzenithbank.com58%65%15%37%
UK Dept for Educationeducation.gov.uk55%50%70%37%
City of Houstonhoustontx.gov52%50%15%37%
Police National Legal Databasepnld.co.uk47%35%15%40%
City of Atlantaatlantaga.gov42%25%15%37%
TaylorMadetaylormade.com42%25%15%37%
DC Public Schoolsdcps.dc.gov30%0%15%42%

Patterns:

  • Transport ≤15% on 10 of 14 domains — spoofed “breach notification” and municipal/airline mail remain easy to deliver even when claims are fake.
  • Strongest overalls: Bonava 76%, Frontier 74%, Viavi 70% — still short of 100%.
  • Weakest: DCPS 30% (0% identity) and Atlanta / TaylorMade at 42%.
  • Microsoft 68% with 90% identity is relatively strong on spoofing controls, but website score lags.

Illustration: multi-org domain audit scoreboard with none at 100% ideal

Audit links: microsoft.com · houstontx.gov · flyfrontier.com · zenithbank.com · atlantaga.gov · dcps.dc.gov

MFA: YubiKey & Google Authenticator (spotlight)

Public docs only for the highest-visibility names. Grade: Fail = SMS/voice/email OTP; Partial = vendor soft token / push without open TOTP or YubiKey; Pass = open TOTP; Strong = FIDO/YubiKey.

OrganizationYubiKey / FIDOOpen TOTPGrade
MicrosoftYes (FIDO2)YesStrong
Zenith BankProprietary e-Token / hardwareNoPartial
Allstate (workforce)Hardware + MS AuthenticatorNo (not open TOTP)Partial
Frontier AirlinesNot documentedNo (email/SMS codes reported)Fail
City of HoustonNot documentedNot documentedUnevaluated

Takeaway: Even if ExfilSquad’s dumps are hoaxes, residents and customers still need strong MFA on real bank, airline, and Microsoft accounts. Proprietary tokens (Zenith) and workforce Microsoft Authenticator (Allstate) are better than SMS-only — but vendor-locked apps without open TOTP are not a Pass, and SMS-class airline login codes remain a Fail.

Website stack note

Passive website-tech probes on August 2, 2026 across all 14 domains:

HostNotable signal
dcps.dc.govDrupal 7 (EOL / far behind current Drupal)
ncl.ac.ukHubSpot; jQuery 1.10.2 EOL hint
Other 12 hostsNo notable CMS/PHP aging bullets in this pass

Stack age does not prove ExfilSquad access. Outdated Drupal at DCPS is still a hygiene flag worth fixing independently.

Lookalike / cybersquat scans

Brand domainLookalikes to reviewNotes
houstontx.gov8houstontx.com / .net / .io and peers registered — spoof-adjacent for city phishing
flyfrontier.com40Dense typo-squat set (flyfronteir.com, flyfroniter.com, …) with MX on many
microsoft.com45 (27 point at brand)Microsoft already defensively owns many omissions/TLD swaps

Fake “City of Houston data breach help desk” or “Frontier miles recovery” sites on lookalikes are the practical risk from this campaign — whether or not any dump is authentic.

Priority actions

If you live in Houston or fly Frontier:

  • Ignore cold calls/emails citing ExfilSquad, “6 million Houston records,” or “Frontier 2.4M leak payout.” Verify only via houstontx.gov or flyfrontier.com published channels.
  • For Frontier’s confirmed earlier incident, see Frontier lawsuits / Scattered Lapsus$ Hunters.
  • Prefer authenticator apps / FIDO over SMS for Microsoft, banking, and insurance logins.

For named organizations:

  • Publish a short confirm / deny / investigating statement — silence amplifies leak-site fiction.
  • Assume phishing spikes: DMARC p=reject, MTA-STS enforce, and callback-only verification for aid, payroll, and municipal payments.
  • Drive domain scores toward the 100% ideal; transport at 15% is the recurring gap on this list.

Protect inboxes during unverified leak-site waves.

Run a free Instant Cybersecurity Audit at audit.emailmenow.com or contact EmailMeNow IT Consulting.


Sources: GalaxyWarden — ExfilSquad tracker · GalaxyWarden — City of Houston listing · RuntimeWire — Microsoft claim unverified · IT-Connect — ExfilSquad / Microsoft evidence thin · WatchGuard — ExfilSquad profile · EmailMeNow audits Aug 2, 2026