Hackers steal sensitive data from UK Department for Education and police

by | Jul 29, 2026 | Technology

Hackers steal sensitive data from UK Department for Education and police

A previously unknown hacking group called ExfilSquad claimed responsibility for breaching the Department for Education and the police national legal database, exposing sensitive information belonging to government personnel, educational staff, and law enforcement officers. The attack resulted in the theft of more than 740,000 pieces of data across multiple systems and databases.

The Department for Education incident involved the compromise of just over 600,000 records from its help-desk portal, containing contact information such as names, email addresses, phone numbers and job titles belonging to parents, staff, government officials and senior school leaders. An additional breach of the department’s Turing portal, which administers a student exchange program, resulted in a smaller data theft. The police national legal database experienced a separate intrusion affecting approximately 135,000 records, including work contact details of police officers and criminal justice personnel. The database also contained information from members of the public who had previously used the Ask the Police service.

The attackers posted samples of the stolen data on a website and issued demands for payment to multiple victims, including the Department for Education and the police legal database operators. The hackers threatened to release the full dataset unless an unspecified payment was made, characterizing the ransom demand as minimal compared to potential litigation costs. Cybersecurity firm Sophos verified that the posted data samples appeared legitimate, though an associated social media account attributed to the group was subsequently suspended.

Authorities and affected organizations initiated response measures following the discovery of the breach. The Department for Education stated that swift containment measures had been implemented and emphasized that compromised information was limited to customer service contact details. No evidence of ransomware deployment was identified in the attack on the department’s systems. Both the Department for Education and the police legal database reported the incidents to the Information Commissioner’s Office, and the government coordinated with the National Cyber Security Centre and National Crime Agency on the investigation. Officials characterized the police database breach as relatively low-risk, noting that the system did not contain information about confidential victims, witnesses, or offenders.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI