ExfilSquad, a cybercrime group that emerged in mid-2026, has targeted 13 organizations across the U.S., UK, and Sweden, exploiting cloud portals to steal sensitive data. The group's tactics involve threatening to publish the stolen information on a dark web leak site unless a ransom is paid, rather than using traditional ransomware methods. This approach allows ExfilSquad to amplify the damage by sharing the data via torrents, putting additional pressure on victims to comply with their demands. The list of targeted organizations includes a major financial institution in Nigeria, which was breached in July. ExfilSquad's activities are being tracked by Resecurity, which has been monitoring the group's movements since its emergence1. The use of cloud portal exploitation and data theft highlights the need for organizations to reassess their cloud security measures to prevent such breaches, making it essential for practitioners to prioritize cloud security to mitigate the risk of data theft and extortion.