LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surface
Recent BreachesData breach tracker

Recent Breaches › Viavi Solutions Listed by ExfilSquad Ransomware Group

HIGH severityUnverified claimHow we verify

Viavi Solutions Listed by ExfilSquad Ransomware Group: What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·July 26, 2026
Viavi Solutions Listed by ExfilSquad Ransomware Group

Reported July 26, 2026.

HIGH
Severity
1
Data types exposed
July 26, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Viavi Solutions was listed by the ExfilSquad ransomware group on July 26, 2026, after internal files were exfiltrated in an attack. Individuals connected to the company should review any notifications and take appropriate steps to protect their information.

Severity & verification
HIGH severityUnverified claim
Contact / identity PII exposed.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Was your email in the Viavi Solutions Listed by ExfilSquad Ransomware Group breach?
See every leak tied to your email — not just this one. 15-second check, no card, no account.

When a company that works deeply inside other organisations’ networks appears on a ransomware group’s leak site, the immediate question for customers, partners and employees is simple: was my information taken, and what can someone do with it? Public reporting on 26 July 2026 stated that Viavi Solutions had been listed by the group known as ExfilSquad, which claimed to have exfiltrated internal files in a ransomware attack. The number of people affected remains unknown, yet a related data summary points to roughly 430,000 records that include customer and partner contact information, significant personally identifiable information, and enterprise account identifiers. For anyone who has done business with or worked for Viavi, that combination raises concrete risks of phishing, account takeover and further social-engineering attempts.

Exact confirmation of what left the company’s systems, and whether the listing reflects a completed extortion or an unverified claim, has not been independently established in the available public record. What follows sets out only what has been reported, places the claim in context, and outlines practical steps for people who may be affected.

Inside the incident

According to public reporting dated 26 July 2026, Viavi Solutions was listed by the ExfilSquad ransomware group. The group’s claim is that internal files were exfiltrated in a ransomware attack. No detailed timeline of intrusion, dwell time, or encryption event has been disclosed in the material available. The number of individuals affected is listed as unknown. A data summary associated with the reporting describes approximately 430,000 records said to contain customer and partner contact information, significant personally identifiable information, and enterprise account identifiers. Beyond that summary and the characterisation of the material as “internal files,” no further inventory of file names, systems, or dollar figures tied to ransom demands has been made public. Whether Viavi has authenticated the claim, negotiated, or restored systems from backups is not stated in the reported facts.

Who is ExfilSquad?

ExfilSquad is presented in open reporting as a ransomware operation that follows the now-common double-extortion model: data is copied out of a victim environment before, or instead of, encryption, and the group then threatens to publish or sell the material if payment is not made. Like other actors in this category, such groups typically advertise victims on dedicated leak sites, post samples or file listings to increase pressure, and sometimes auction access or data to other criminals. Public documentation of ExfilSquad’s earlier campaigns and toolsets is limited compared with longer-established brands; therefore any specific technical claims about how this particular intrusion was performed remain unverified. In the present case, the only assertion tied directly to Viavi Solutions is the group’s own listing and the description of exfiltrated internal files. That listing should be treated as a claim until corroborated by the organisation or by independent forensic disclosure.

About Viavi Solutions

Viavi Solutions is a publicly described technology company operating in network testing, monitoring, and assurance. Organisations in this sector commonly supply instruments, software, and services that help telecommunications providers, enterprises, and government customers measure and secure the performance of wired and wireless networks. Reported revenue associated with the company in the breach summary is given as approximately $1 billion, indicating a substantial global footprint and a large base of commercial and partner relationships. Because Viavi’s products and services sit inside customer environments and often involve support contracts, professional services, and account management, the company typically holds business contact data, contractual records, and technical configuration details. A breach affecting such an organisation is consequential not only for its own workforce but for the many external parties whose details appear in CRM systems, partner portals, and support databases.

What was likely exposed

The facts name the exposed material as internal files exfiltrated in a ransomware attack. The accompanying data summary states that roughly 430,000 records contain customer and partner contact information, significant personally identifiable information, and enterprise account identifiers. No further breakdown—such as whether the PII includes government identifiers, financial account numbers, or authentication secrets—has been disclosed. Organisations of Viavi’s type ordinarily maintain employee directories, customer and partner contact lists, contract and billing identifiers, support-ticket histories, and sometimes technical documentation that references customer network environments. It is reasonable to expect that some mixture of those categories could be present in “internal files,” yet the precise contents remain unconfirmed. Readers should not assume that any specific data element about them was or was not included until Viavi or a regulator provides an authoritative notice.

What's at stake

For individuals whose names, email addresses, phone numbers or employer affiliations appear in the described records, the most immediate risks are targeted phishing and social-engineering calls that reference real business relationships. Attackers who possess both contact data and enterprise account identifiers can craft messages that look like legitimate support or billing correspondence, increasing the chance that credentials or further personal data will be surrendered. Significant PII, if present, can also be reused for identity-fraud attempts or sold onward. For Viavi itself, the stakes include potential regulatory notification duties, contractual obligations to customers and partners, remediation costs, and erosion of trust among organisations that rely on its measurement and assurance products. Because the scale of affected people is still listed as unknown, the full scope of downstream exposure cannot yet be measured.

Were you affected?

If you are a current or former employee, customer, or partner of Viavi Solutions, treat unsolicited messages that reference the company or your business relationship with heightened caution. Prefer official channels you already trust, enable multi-factor authentication on email and work accounts, and monitor financial and credit statements for unfamiliar activity. Watch for breach-notification letters or emails from Viavi; those remain the authoritative source for whether your specific data was involved. As an additional check, you can run a free exposure scan of your email address to see whether it has already appeared in other known breach datasets, which may help you prioritise password changes and monitoring. Public detail on this incident is still limited; further clarity will depend on official statements from the organisation and any subsequent regulatory filings.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyViavi Solutions security record
64/100
DoxxScan™ · Moderate doxx risk
B- 76Above-average record

1 reported incident on record.

See Viavi Solutions’s full breach history →

More recent breaches

Analog Devices Listed by ExfilSquad Ransomware GroupJuly 26, 2026Microsoft Listed by ExfilSquad Ransomware GroupJuly 26, 2026Wesco International Listed by ExfilSquad Ransomware GroupJuly 26, 2026City of Houston Listed by ExfilSquad Ransomware GroupJuly 26, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Viavi Solutions Listed by ExfilSquad Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by exfilsquad — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram