Data breach
TaylorMade & Sun Day Red
- Records
- 439,517
- Breach date
- 26 July 2026Estimated
- Added
- 9 August 2026
What was exposed
4 types of data · 2 more reported
- Email addresses439,517
- Names396,005
- Phone numbers344,396
- Street addresses326,587
- Purchase historyReported, not counted
- Private messagesReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
The data extortion group ExfilSquad has claimed responsibility for a breach affecting TaylorMade and its apparel brand Sun Day Red, according to our investigation team, which indexed the listing on August 9, 2026. The group first named taylormadegolf.com on its leak site on July 26, 2026, and our team estimates the attack occurred on or around that date. The listing tied to the breach contains 439,517 rows. Unlike ransomware crews that encrypt systems, ExfilSquad appears focused on stealing data and pressuring victims into paying.
Independent researchers have lent weight to the group's claims. Analysts at Fortra obtained data samples released by ExfilSquad and concluded the material appears genuine, likely taken from Microsoft Dynamics 365 CRM and ERP systems rather than through a full network compromise. The leading theory, per Fortra, is that the attackers exploited misconfigured Microsoft Power Pages portals that allowed public read access. Fortra found no evidence of ransomware encryption or lateral movement. The TaylorMade dataset appeared among dumps of 13 victim organizations that the group published via torrent on August 7, 2026.
July 26, 2026: ExfilSquad publicly names TaylorMade & Sun Day Red on its leak site; ransomware.live records the listing the same day.
July 28, 2026: ExfilSquad releases data samples and sets an August 5 deadline for communication, according to Fortra researchers.
August 7, 2026: The group publishes data dumps for 13 victims, including a TaylorMade archive, via torrents.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses, phone numbers, names, and street addresses. Emails were present for all 439,517 rows in the listing, with phone numbers for 344,396 records, names for 396,005, and street addresses for 326,587.
ExfilSquad's leak listing describes a larger set of materials in the full archive, including customer support history, orders, shipping information, business account data, financial and account information, internal notes, attachments, and AI support chat transcripts. Fortra's analysis of the released samples is consistent with those descriptions.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Email addresses and phone numbers exposed in bulk are typically used for phishing and smishing campaigns. Because the listing also includes names and street addresses, scammers can craft convincing messages that reference real details to build trust.
The more sensitive risk comes from the support histories, orders, and financial information ExfilSquad claims to hold. Attackers with access to order and support records can impersonate a company's customer service team, reference a real purchase, and trick people into revealing payment details or account credentials. Internal notes and chat transcripts may also expose details individuals shared in support conversations. Anyone affected should treat unsolicited contact claiming to be from TaylorMade, Sun Day Red, or a retailer with suspicion, and should not click links or share account details in response to unexpected messages.
What Should You Do If You Were Affected?
Watch for phishing emails or texts that reference orders, golf equipment, or customer support. Verify any claim by contacting the company through its official website directly, not through links in messages.
If you reused a password tied to your TaylorMade or retailer accounts, change it now and enable two-factor authentication where offered.
Review bank and card statements for unfamiliar charges, particularly if financial or account information was part of records tied to you.
Be cautious with identity details in scam calls or mail, since street addresses are in circulation. Do not confirm personal information to unsolicited callers.
In the news
- Fortra Intelligence: ExfilSquad data extortion group analysisfortra.com (opens in a new tab)
- ransomware.live victim listing for TaylorMade & Sun Day Red golfransomware.live (opens in a new tab)
- Breachsense: ExfilSquad ransomware group trackingbreachsense.com (opens in a new tab)
- DeXpose: ExfilSquad targets TaylorMade & Sun Day Red golfdexpose.io (opens in a new tab)
- The Arabian Post: ExfilSquad data leaks substantiate broad breach claimsthearabianpost.com
