A cyberattack on the UK Department for Education and a police database has exposed more than 740,000 pieces of sensitive data, including names, emails, and job titles of government officials, police officers, and school leaders. The breach, claimed by a group calling itself ExfilSquad, highlights growing risks to public-sector information systems.
Scope of the Data Breach
Hackers stole over 600,000 lines of data from the Department for Education’s help-desk portal, revealing parent and staff contacts. A smaller package was taken from the Turing portal, which manages student study-abroad programs. Separately, the police national legal database (PNLD) was breached, compromising 135,000 records of police officers and criminal justice workers.
Get the #1 Wireless Door Camera
REOLINK Bestseller: 2K Weatherproof Video Doorbell, No Monthly Fees.
What Information Was Exposed?
According to the leak site set up by ExfilSquad, the stolen data includes full names, work and personal email addresses, phone numbers, and job titles. Some members of the public who used the Ask the Police service also had their names and addresses taken. No confidential victim, witness, or offender information was stored on the compromised databases, reducing immediate risks to ongoing investigations.
Comparison of Breached Databases
| Database | Records Stolen | Data Types |
|---|---|---|
| Department for Education Help-Desk Portal | 600,000+ | Names, emails, phone numbers, job titles |
| Department for Education Turing Portal | Smaller package | Similar contact data for students and staff |
| Police National Legal Database (PNLD) | 135,000 | Names, work emails, force details, public queries |
Who Is ExfilSquad?
ExfilSquad is a previously unknown hacking gang that claimed responsibility. They posted samples of the data on a leak site and demanded a payment from the DfE and PNLD to avoid full publication. This ransomware-like tactic is typical of cybercriminals seeking financial gain from stolen data. The group described the requested amount as a “rounding error,” according to screen grabs seen by the Guardian.
Key Takeaways for Organizations
- Public sector entities must strengthen cybersecurity defenses against sophisticated attacks.
- Employee data, even non-sensitive contacts, can be weaponized for phishing and social engineering.
- Regular security audits and multi-factor authentication reduce breach risks.
- Incident response plans should include communication with affected individuals promptly.
FAQ
What was stolen in the UK government cyberattack?
Over 740,000 records were taken, including names, emails, phone numbers, and job titles from the Department for Education and police legal databases. No classified or criminal case details were exposed.
Who is behind the ExfilSquad hack?
ExfilSquad is a newly emerged hacking group that claimed the attack. They posted sample data and demanded payment from the UK government to prevent full public release.
How can individuals protect their data after this breach?
Be alert for phishing emails or calls using your stolen information. Enable multi-factor authentication on accounts, monitor for suspicious activity, and change passwords regularly. Organizations should conduct security training and patch vulnerabilities.
The breach underscores the importance of proactive cybersecurity in protecting public trust. As investigations continue, affected agencies are working to notify individuals and enhance system protections against future attacks.