A cyber attack targeting the UK’s Department for Education (DfE) last week resulted in the theft of more than 600,000 records, including names and email addresses of government officials, senior school leaders, university staff, and members of the public. The breach, attributed to a previously unknown hacking group called ExfilSquad, involved data from the DfE’s help desk and the Turing Scheme portal, which manages information on British students studying abroad.
The stolen information, posted on the dark web by the hackers, comprises primarily customer service contact details. According to the department, the variety of data sets involved are disparate and cannot be easily connected to create a comprehensive profile of individuals. The DfE has emphasized that no sensitive or confidential data outside these contact details were accessed.
The attack also affected the Police National Legal Database (PNLD), where around 135,000 entries were reportedly compromised. The PNLD, which supports UK police forces with legal resources, confirmed that the breach involved the names, work email addresses, and affiliations of police officers and criminal justice staff, along with some personal details of members of the public who used the “Ask the Police” service. The police database does not store sensitive information on victims, witnesses, or offenders, and authorities consider the breach less serious compared to the education department’s data loss.
ExfilSquad has reportedly demanded a ransom from the DfE, PNLD, and other victims, threatening to release additional data if payment is not made. The group has attempted to leverage the stolen information as part of typical cybercriminal extortion tactics.
In response, the Department for Education reported that it took swift action to contain the incident and temporarily suspended affected online services, switching to telephone contact while remediation efforts are underway. The department is working closely with the National Cyber Security Centre (NCSC), the National Crime Agency (NCA), and has self-referred the breach to the Information Commissioner’s Office (ICO). The PNLD has also notified the ICO and is cooperating with security agencies.
Cybersecurity experts have pointed to this breach as indicative of persistent vulnerabilities in government systems. Jake Moore, a global security adviser at cybersecurity firm ESET, noted that the attack demonstrates ongoing challenges for UK government departments to adequately safeguard sensitive data, highlighting a similar incident targeting the Foreign Office last year.
The NCSC has reported a marked increase in the number of cyberattacks classified as “nationally significant,” rising from 63 in 2022 to 204 in 2025, with “highly significant” incidents increasing from one to 18 over the same period. The surge has been attributed to more widely available advanced hacking tools and growing reliance on third-party IT suppliers.
The DfE maintains that it has established robust processes to protect information and that the exposed data pertains only to customer service contacts, not sensitive personal or confidential information. Nevertheless, the incident underscores continuing cyber risks faced by public sector organizations, particularly those holding large quantities of personal information.
