ExfilSquad has recently escalated its operations by announcing new victims in the Wesco data breach saga, setting a deadline of August 5, 2026, for negotiations to conclude. If the deadline is not met, the stolen data will be released into the public domain. Among the 13 organizations affected are notable entities from the United States, the United Kingdom, and Sweden, including Wesco International.
According to Resecurity, ExfilSquad emerged in mid-2026, distinguishing itself from typical ransomware groups. Rather than employing encryption tactics, this group opts for extortion through the publication of stolen data on an onion site dedicated to leaks. In a notable shift, the group has expanded its distribution methods beyond TOR; they have included torrent links for each victim, facilitating peer-to-peer sharing and complicating efforts to remove the data from the internet. Resecurity reports that on August 7, 2026, ExfilSquad released several torrent files for each affected organization.
Data Breach of Wesco and Other Victims
The list of victims released by ExfilSquad includes Wesco International, the UK Department for Education Help Portal, Turing Portal, Police National Legal Database, Allstate, TaylorMade, Sun Day Red Golf, Frontier Airlines, District of Columbia Public Schools, Newcastle University, Viavi Solutions, City of Houston, City of Atlanta, and Bonava.
For Wesco International, the group claims to have obtained 2.6 million records, detailing customer and employee information, CRM data, contact details, user profiles, credit and business identifiers, authentication metadata, and access information. The Department for Education Help Portal is reported to have around 600,000 records compromised, while the City of Houston faces a staggering 6 million records at risk.
Interestingly, some victims experienced more unusual data breaches. In the case of the District of Columbia Public Schools (DCPS), the system was compromised, affecting student data; however, ExfilSquad refrained from releasing complete records of minors, opting instead to publish only “cleansed” fragments of individual records.
Why Torrents Have Become Part of the Scheme
Resecurity highlights that the use of torrents for data publication enhances accessibility for journalists, researchers, and other malicious actors. Once a file enters the P2P network, it becomes nearly impossible to remove, as other participants can continue to share the data.
Researchers note that ExfilSquad assigns a unique torrent tracker and initial web seed for each victim. On August 7, the report indicated that some of the most active hosts were located in China and Russia, with Resecurity later identifying over 50 seed nodes involved in the distribution.
In July, ExfilSquad claimed to have breached a bank in Nigeria, although these assertions later vanished from their leak site. Resecurity also indicates awareness of at least two other victims who appear to have engaged in negotiations with the group.
Related Materials: The news editor specializing in software analytics, streaming services, and changes in global technology platform policies, Marta, provides in-depth coverage of Windows updates, functional changes in Spotify and Google, and explores issues surrounding antitrust regulations in app stores. With over 140 publications, she assists users in navigating the rapidly evolving landscape of digital services.