On July 26, 2026, the ExfilSquad ransomware group listed Microsoft on its leak site, claiming to have exfiltrated internal files. The alleged breach involved approximately 8 million entries.
The reported exposed data categories include PII, employee and customer contact information, authentication data, password hashes, portal identities, corporate account information, business leads, facilities management records, internal service tickets, and access permissions. The specific systems or business units affected have not been detailed. No official public breach notification from Microsoft has been identified.
Details regarding the exact number of affected individuals, specific states impacted, and confirmation of data types such as SSNs, medical records, or financial data remain unconfirmed. Further information may emerge as the situation develops, but Microsoft had not issued a public breach notification at the time of the report.