Hackers steal sensitive data from UK Department for Education and police

by | Aug 5, 2026 | Technology

Hackers steal sensitive data from UK Department for Education and police

The UK Department for Education and the Police National Legal Database have fallen victim to a cyber-attack resulting in the exposure of more than 740,000 records. The stolen information includes contact details and identifying information belonging to government officials, school leaders, university staff, law enforcement personnel, and members of the public.

Approximately 600,000 records were taken from the DfE’s help-desk portal, containing names, email addresses, phone numbers, and job titles of parents and staff. An additional smaller data set was compromised from the department’s Turing portal, which administers a program for students studying overseas. The police legal database breach yielded approximately 135,000 records, including names, work email addresses, and organizational affiliations of police officers and criminal justice sector employees. Some members of the public who had submitted inquiries to the Ask the Police service were also affected.

A previously unknown hacking organization calling itself ExfilSquad has claimed responsibility for the attack and established a leak website displaying samples of the stolen data. The group is demanding an unspecified payment from the DfE, PNLD, and other identified victims in exchange for not publishing the complete dataset. According to communications reviewed by cybersecurity analysts, the hackers are threatening to release all stolen information unless payment is made, characterizing it as a minor expense relative to potential litigation costs.

The DfE stated that immediate actions were undertaken to contain the incident and emphasized that only customer service contact information had been compromised. The department indicated no additional sensitive data had been accessed. Security analysts noted that the help-desk data consists of separate datasets that cannot be easily cross-referenced. The PNLD breach also resulted in the theft of access passwords for the database system.

Both organizations have reported the incidents to the National Cyber Security Centre, the National Crime Agency, and the Information Commissioner’s Office. Officials indicated it remains early in the investigation, with the DfE showing no evidence that ransomware was deployed during the attack.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI