Key facts
- Over 740,000 records of sensitive data were stolen from the UK's Department for Education and a police legal database.
- The stolen data includes contact information for government officials, educators, police officers, and members of the public.
- Hackers, identifying as ExfilSquad, are demanding payment to prevent the full release of the compromised data.
- The Department for Education's help-desk and Turing portals, along with the police national legal database (PNLD), were breached.
- The government is collaborating with cybersecurity agencies to investigate and contain the incident.
A significant cyber-attack has compromised sensitive data from the UK's Department for Education (DfE) and the police national legal database (PNLD), with hackers claiming to have stolen over 740,000 records. The breach exposed personal details of government officials, senior school leaders, university staff, police officers, and members of the public.
The hackers, operating under the name ExfilSquad, posted samples of the stolen data on a leak site and are demanding an unspecified payment from the victims to prevent the full release of the information. According to the hackers' message, the requested payment is minimal compared to potential litigation costs from a data leak.
Data stolen from the DfE's help-desk portal and Turing portal includes full names, email addresses, phone numbers, and job titles. The PNLD breach, which provides legal assistance to UK police forces, also saw the theft of similar data, including names, employing organizations, and work email addresses of police officers and criminal justice personnel. The PNLD stated that confidential victim or witness information was not compromised, and the risk associated with this specific breach is considered low, though the reuse of passwords for other sensitive systems is a concern.
Sophos, a cybersecurity firm, has indicated that the data samples appear legitimate. While an account associated with the group on X was suspended, the group's tactics are typical for cybercriminals seeking financial gain. The DfE has stated that swift action was taken to contain the incident and that only limited customer service contact details were accessed, with no other data compromised. The government is working closely with the National Cyber Security Centre and the National Crime Agency, and the incident has been reported to the Information Commissioner's Office.