ExfilSquad Microsoft Breach Claim Gains Credibility After 4,000-Row Data Archive Emerges
ExfilSquad’s claim that it breached Microsoft has gained credibility after researchers analyzed a new archive containing 4,000 data rows dated July 27. The dataset includes Dataverse OData annotations, wide field schemas, and internally consistent identifiers that indicate the records are authentic rather than fabricated.
The group launched on July 26 with roughly 15 victim claims, which researchers initially dismissed as fabricated due to a lack of supporting evidence. The new sample appears to originate from a partner-facing portal and a pre-production tenant rather than the company’s corporate core. Separate reporting also confirmed that ExfilSquad’s alleged breach of the UK Department for Education is legitimate.
From the sources (2 posts)
@darkwebinformer‼️🇬🇧 ExfilSquad ransomware earlier this week claimed a lot of big companies including the UK's Department of Education. While there was doubt on many of these claims, it seems the DfE hack is legitimate. Source: ht
@intcyberdigestBREAKING: Microsoft has allegedly been breached. We have analysed the samples from ExfilSquad's alleged Microsoft breach. ExfilSquad launched on July 26, 2026, with roughly 15 victim claims in a single day, Microsoft among them. Researcher