The UK Department for Education is currently dealing with a significant data breach as cybercriminals claim to have exfiltrated over 600,000 records. These records reportedly include names, email addresses, and phone numbers from two departmental portals: the DfE Help Desk Self-Service Portal and the Turing Scheme Portal. However, a spokesperson clarified that the figure represents lines of data, not necessarily individual people, and emphasized that the risk to individuals remains low.
The group behind the attack, known as ExfilSquad, is demanding a ransom to prevent the release of the compromised data. While there is no indication that the systems were encrypted, the threat of exposure is concerning. In a related incident, the Police National Legal Database was also breached, affecting 135,000 pieces of data that could identify police officers and others in the criminal justice system, though it did not contain sensitive information about investigations or witnesses.
The National Cyber Security Centre is actively supporting law enforcement in responding to the PNLD breach. The UK government maintains a strict policy against paying ransoms, aligning with recent moves to make such payments illegal for public sector entities and critical infrastructure organizations. Despite this policy, the frequency of ransomware attacks on central government agencies has decreased in recent years, with only four incidents reported in the two years following 2023.
The Department for Education has assured the public that robust measures are in place to protect information and that swift action was taken to contain the breach. The data involved is limited to customer service contact details, and no other sensitive data has been accessed.


