ON
← Back to feed
Young cyber gang claims data theft at Microsoft
Germany🏛️ PoliticsCenteryesterday

Young cyber gang claims data theft at Microsoft

A new cybercriminal group called 'ExfilSquad' has claimed to have stolen sensitive data from Microsoft, including personal information, employee details, customer data, authentication credentials, and internal documents, and is now demanding ransom. The group reportedly stole 130 gigabytes of unprocessed data containing around eight million entries. However, there is currently no concrete evidence to verify these claims, and Microsoft has not yet commented. The report notes that this is not the first time such false accusations have been used as a tactic to extort money, citing a similar case involving another group named 'Playboy' who falsely accused the DIHK of a data breach.

A previously unknown cybercriminal group has claimed to have stolen sensitive data from Microsoft, according to its dark web presence. The group, calling itself ExfilSquad, asserts that it accessed 130 gigabytes of uncompressed data containing approximately eight million entries. These include personal information, employee and customer details, authentication credentials, password hashes, portal identities, business account information, contact details, building management records, internal service tickets, and access rights. The group's claims were made public through their dark web page, where they demand ransom payments in exchange for the purported data. According to reports, ExfilSquad appears to be a newly formed collective, having emerged recently in the underground digital space. Their announcement follows similar tactics used by other cybercriminal groups who have attempted to extort money by falsely claiming data breaches. The nature of the alleged breach remains unclear. It is uncertain which specific systems within Microsoft were targeted, nor is there clarity on how recent the data might be. Additionally, the extent to which employees' and customers' information could have been compromised is still unknown. The volume of data mentioned, while substantial, appears relatively small compared to the scale of operations at a global tech giant like Microsoft. Microsoft has yet to officially comment on these allegations. When contacted by heise security, the company was unable to provide immediate responses. A formal statement is pending and will be released once available. This is not the first time such claims have surfaced. In late 2024, a new cybergroup named Playboy similarly asserted that it had stolen data from the German Chamber of Industry and Commerce (DIHK). However, affected parties found no evidence supporting this claim. Such incidents highlight the growing challenge of distinguishing genuine data breaches from extortion attempts by unidentified actors. Cybersecurity experts often caution against taking all such claims at face value. While some groups may indeed possess stolen data, others resort to bluffing to extract financial gain. Verification typically requires independent investigation, which can be complex given the anonymity afforded by dark web platforms. The emergence of ExfilSquad underscores the evolving landscape of cybercrime, where new threats continually surface with varying degrees of legitimacy. As more organizations become targets, the need for robust cybersecurity measures becomes increasingly critical. Companies must remain vigilant against both known and emerging threats while ensuring transparency in case of actual breaches. Authorities and cybersecurity firms continue to monitor developments related to this incident. Any further actions taken by ExfilSquad or responses from Microsoft will likely influence future strategies in combating such cyber threats. Until then, the situation remains under review, with ongoing assessments being conducted to determine the validity of the claims made by the cybercriminal group.

How each side covered it

The same event, grouped by the political lean of the outlets covering it.

How each side covered it

Support independent, bias-aware news and unlock the social pulse, community voting, and your personalized For You feed.

Become a Supporter

Covered around the world

The same event as reported in other countries.

Covered around the world

Support independent, bias-aware news and unlock the social pulse, community voting, and your personalized For You feed.

Become a Supporter

Claims check

Key factual claims, and how many sources assert vs dispute each.

Claims check

Support independent, bias-aware news and unlock the social pulse, community voting, and your personalized For You feed.

Become a Supporter

1 reports

heise online logoheise onlineIndependentCenterFactual 65Objective 70yesterday
Young cyber gang claims data theft at Microsoft

A new cybercriminal group called 'ExfilSquad' has claimed to have stolen sensitive data from Microsoft, including personal information, employee details, customer data, authentication credentials, and internal documents, and is now demanding ransom. The group reportedly stole 130 gigabytes of unprocessed data containing around eight million entries. However, there is currently no concrete evidence to verify these claims, and Microsoft has not yet commented. The report notes that this is not the first time such false accusations have been used as a tactic to extort money, citing a similar case involving another group named 'Playboy' who falsely accused the DIHK of a data breach.

Bias read (Center): The article presents the claim by the cybercriminal group without taking a clear stance on the validity of their allegations. It highlights the lack of verification and the possibility that this could be a bluff, which suggests a balanced approach. There is no overt ideological framing or emphasis,故

Why factuality (65): The article reports on a claimed data breach by a new ransomware group called ExfilSquad against Microsoft, citing specific types of data allegedly stolen. While no primary source is available, the information aligns with known patterns of ransomware groups making similar claims. The article acknowl

Why objectivity (70): The tone remains relatively neutral, presenting the situation as a reported claim without overt bias. It includes skepticism about the credibility of the group and the scale of the alleged breach, but avoids strong emotional language. The article also mentions past attempts by cybercriminals to exto

Keep the news honest.

ObjectiveNews is reader-funded and ad-free — we show you the bias instead of hiding it. Support independent journalism for €5/month.

Become a Supporter

Related stories