Skip to main content
ExfilSquad Compromise of the Bonava Group

ExfilSquad Compromise of the Bonava Group

On July 26, 2026, the ExfilSquad ransomware group claimed compromise of Bonava Group, a Northern European residential developer. According to the group’s leak site, the attack resulted in the exfiltration of approximately 842,000 records. Analysis of the likely intrusion path reveals that multiple Bonava employee credentials, including those for the company’s Citrix Cloud remote access gateway and Microsoft 365 tenant, had been harvested by infostealer malware and available in dark web credential markets months before the breach was claimed.


Key Findings
#

The Breach
#

ExfilSquad claimed Bonava on their leak site on July 26, 2026, alleging exfiltration of ~842,000 records including PII, property ownership data, contractor information, warranty cases, and customer service records. ExfilSquad operates a data-extortion model: theft and threatened publication without system encryption. No operational disruption was reported, consistent with this approach.

ExfilSquad’s documented TTPs across multiple victims include initial access via credential abuse or phishing, lateral movement through enterprise environments, and bulk data exfiltration. They claimed at least one other major victim (Analog Devices, ~570,000 records) on the same date, suggesting coordinated disclosure timing rather than simultaneous operations.

Infostealer Credential Exposure
#

The most significant finding is the presence of Bonava employee credentials in multiple dark web infostealer log compilations, with entries dating from early 2026, well before the breach claim. At least two distinct device infections (identifiable by unique infection IDs) harvested credentials from Bonava employees.

The harvested data included:

  • Citrix Cloud StoreFront credentials: plaintext passwords paired with the URL bonavaab.cloud.com/citrix/storeweb/, Bonava’s remote access gateway
  • Microsoft 365 / Azure AD credentials: authentication against login.microsoftonline.com with Bonava’s tenant ID (cb0bb6f8-****-****-****-5ff0***a4b03)
  • Autodesk, Yammer, ArcGIS, BIMcollab, and Hilti OnTrack credentials: indicating the infected devices belonged to technical/construction staff with broad system access

The credentials appeared across at least six distinct compilation datasets distributed through common cybercrime channels between February and July 2026. Multiple passwords followed predictable patterns (keyboard-walk variations, year-appended words, personal life references such as children’s names combined with birth years), suggesting both weak password policies and a lack of enforced complexity requirements that would prevent personally meaningful but easily guessable credentials.

The Citrix Gateway as Entry Point
#

Bonava’s Citrix Cloud environment at bonavaab.cloud.com represents the most probable initial access vector. Citrix StoreFront provides authenticated users with access to published applications and desktops within the corporate environment, functionally equivalent to being on the internal network.

The combination of:

  • Plaintext credentials for this specific service in dark web markets
  • ExfilSquad’s documented preference for remote access exploitation
  • The absence of indicators suggesting a more complex intrusion method

makes credential-based Citrix access the highest-probability entry point. The fact that credentials were available in plaintext (rather than only as session tokens) suggests MFA was either not enforced or was configured in a bypassable manner on this service.

Microsoft 365 as Reconnaissance and Exfiltration Platform
#

Compromised M365 credentials tied to Bonava’s Azure AD tenant provide access to Exchange Online, SharePoint, OneDrive, and Teams. For a data-theft operation targeting customer and property records, M365 is both a reconnaissance tool (email, org structure, internal documentation) and a potential exfiltration source (SharePoint document libraries, shared drives). The nature of the exfiltrated data, customer records, warranty cases, marketing preferences, is consistent with data stored in cloud collaboration platforms rather than exclusively in on-premises databases.

Pre-Existing Exposure Surface
#

Beyond infostealer data, Bonava’s employee information was extensively available from prior third-party breaches (Apollo.io in 2019, DemandScience, Bureau van Dijk, Nitro PDF). Hundreds of employee records with names, corporate emails, direct phone numbers, office addresses, and LinkedIn profiles were accessible, providing targeting data for phishing or social engineering if credential-based access had failed.

Hudson Rock data indicates 13 third-party credential compromises associated with bonava.com and 21 user-level compromises on bonava.se’s customer portal, indicating a broader pattern of credential exposure across the organization’s ecosystem.

Structural Observations
#

The attack chain likely does not require novel techniques, zero-day exploits, or AI-assisted capabilities. The sequence is:

  1. Commodity infostealer infects employee device (likely via malicious download or phishing)
  2. Malware harvests all saved credentials and session data from browsers
  3. Credentials are sold in bulk on dark web markets
  4. Ransomware operator purchases or acquires relevant credentials
  5. Operator authenticates to Citrix/M365 using stolen credentials
  6. Operator navigates internal environment and identifies data stores
  7. Operator exfiltrates data and posts extortion claim

Each step uses established, well-understood tooling. The defensive failure occurs at steps 1 (endpoint detection), 3 (dark web monitoring/credential rotation), and 5 (MFA enforcement). Any single control at these points would likely have disrupted the chain.


Risk Indicators
#

Technical Indicators
#

  • Citrix Cloud gateway exposed to internet with credential-only authentication (no confirmed MFA)
  • Employee passwords following weak patterns (keyboard walks, year-appended dictionary words, character substitution, personal life references)
  • Multiple employees reusing password variants across services (same root password with minor modifications across Citrix, Autodesk, Yammer)
  • Azure AD tenant ID exposed in credential logs, enabling targeted authentication attempts
  • At least two employee devices infected with infostealer malware without detection or credential rotation

Operational Indicators
#

  • Months-long gap between credential exposure in dark web markets (Feb 2026) and breach claim (Jul 2026), indicating either delayed exploitation or extended dwell time
  • No reported encryption or operational disruption, consistent with data-theft-focused operation
  • Volume of exfiltrated records (842K) suggests access to centralized data stores rather than individual endpoint compromise
  • ExfilSquad’s simultaneous claims against multiple victims suggests batch processing of acquired access

Sources
#

  • DeXpose: ExfilSquad claim reporting and data scope details (dexpose.io)
  • Rescana: ExfilSquad TTP documentation via Analog Devices breach analysis (rescana.com)
  • Cyber News Live: Confirmation of ExfilSquad claim against bonava.se (LinkedIn)
  • Hudson Rock: Infostealer exposure metrics for bonava.com and bonava.se (hudsonrock.com)
  • SOCRadar: ExfilSquad ransomware group profiling (socradar.io)
  • Dark web credential compilations: Multiple infostealer log datasets containing Bonava employee credentials with service URLs
  • Mnemonic passive DNS: Historical infrastructure resolution for bonava.com and bonava.se