ExfilSquad posted 15.1GB of alleged Allstate data to its leak site on July 26 — recruitment files, licensing records, employee accounts. The insurer has confirmed an incident but not the scope.
On July 26, 2026, a ransomware group calling itself ExfilSquad posted a listing on its dark-web leak site claiming it broke into Allstate and walked out with more than 657,000 records — about 15.1 gigabytes of data. Allstate has confirmed it's investigating a cybersecurity incident. What it hasn't confirmed, as of this writing, is whether that number is real.
What ExfilSquad says it has — and what's still unclear
According to the leak-site listing, the stolen dataset covers personally identifiable information alongside recruitment, licensing and onboarding paperwork and internal employee-account details. That phrasing matters: it points toward Allstate's workforce and its network of licensed independent agents rather than customer policy data specifically — though nothing here is confirmed by Allstate, and the company hasn't clarified whether "employee" in ExfilSquad's post means corporate staff, the agent network, or both. No ransom deadline has surfaced in public reporting yet, which is unusual for a group trying to pressure a payout.
657,000+
Records claimed
per ExfilSquad's leak-site post
15.1 GB
Data volume claimed
unverified by Allstate
Jul 26, 2026
Claim posted
Late 2024
ExfilSquad first tracked
Allstate has acknowledged investigating a cybersecurity incident but has not confirmed the scope ExfilSquad claims. · Unsplash
Why insurers keep showing up on leak sites
Insurers sit on exactly the dataset ransomware crews want most: names, Social Security numbers, financial details and — for a company the size of Allstate — a sprawling network of agents and vendors, each one a potential way in. It's the same underlying economics behind Coca-Cola's Fairlife breach and the exploited SharePoint vulnerabilities that keep surfacing this year — large organizations with huge attack surfaces and, in most cases, a third-party system somewhere that wasn't patched fast enough. Once attackers are inside, tools like the recently disclosed AD CS privilege-escalation exploit are exactly the kind of thing that turns one compromised account into domain-wide access.
1
Don't wait for a letter — enable a credit freeze or fraud alert now if you're a current or former Allstate employee, agent, or applicant.
2
Watch for phishing that references real internal Allstate terminology — leaked HR and recruitment data makes for convincing lures.
3
If you're a licensed Allstate agent, assume your licensing and onboarding paperwork may be included — that's more sensitive than a typical customer PII leak.
4
Check Allstate's official breach-notification page directly (type the URL yourself, don't click an email link) once confirmed scope is released.
Has Allstate confirmed the ExfilSquad breach claim?
As of this writing, no. Allstate has confirmed it is investigating an incident but hasn't confirmed the number of records, the data types, or how ExfilSquad got in.
Who is ExfilSquad?
A ransomware and data-extortion group first tracked in late 2024, which has previously targeted organizations in insurance, healthcare and manufacturing using a double-extortion model — steal data, encrypt systems, then threaten to publish.
Is my Allstate policy data affected?
Based on ExfilSquad's own description, the claimed data leans toward recruitment, licensing, onboarding and internal employee-account records rather than policyholder claims data — but that's the attacker's characterization, not a confirmed scope from Allstate.
What should I do if I think I'm affected?
Place a fraud alert or credit freeze, watch for targeted phishing, and wait for Allstate's official notification rather than trusting an unsolicited email.
I've read enough of these leak-site posts to have a rule of thumb: the vaguer a company's early statement, the messier the eventual disclosure tends to be. "Has not confirmed the scope" is not the same sentence as "has ruled out X" — and right now Allstate has said neither. Worth checking back on this one in a few weeks, once a regulatory filing actually shows up.