Hackers steal sensitive data from Department for Education and police
Summarized and contextualized by DistantNews.
At a glance
- Hackers claiming to be ExfilSquad have stolen sensitive data from the UK's Department for Education (DfE) and a police national legal database (PNLD).
- The stolen data includes personal details of government officials, school leaders, university staff, police officers, and members of the public.
- The hackers are demanding payment from the DfE and PNLD to prevent the full release of the stolen information.
A cyber-attack has compromised sensitive data from the UK's Department for Education (DfE) and a police national legal database (PNLD), exposing the personal information of over 740,000 individuals. The breach, claimed by a previously unknown hacking group calling itself ExfilSquad, has targeted government officials, senior school leaders, university staff, police officers, and members of the public.
ExfilSquad claims to have stolen approximately 600,000 lines of data from the DfE's help-desk portal, including parent and staff contact details such as full names, email addresses, phone numbers, and job titles. A smaller dataset was also taken from the department's Turing portal, which manages a student exchange program. Additionally, the hackers assert they obtained 135,000 pieces of data from the PNLD, which provides legal assistance to UK police forces.
The data stolen from the PNLD reportedly includes names, forces or organizations of employment, and work email addresses of police officers and criminal justice personnel. Some names and addresses of members of the public who had previously used the "Ask the Police" service were also taken, though the database is said not to contain confidential victim or offender information. While considered embarrassing, the breach of the police database is not deemed to be serious.
The hackers have posted samples of the stolen data on a leak site and are demanding an unspecified payment from the DfE and PNLD. They warned that the full dataset will be uploaded if their demands are not met, framing the requested payment as a "rounding error" compared to potential litigation costs. Cybersecurity firm Sophos has indicated that the data samples appear legitimate. The DfE has not reported evidence of ransomware being deployed in the attack.
The payment we request of you is simply a rounding error compared to the litigation costs of your data leaking. Be smart and just pay.
Originally published by The Guardian. Summarized and contextualized by our editorial team with added local perspective. Read our editorial standards.