The British Department of Education and Police Department suffer cyber attack, over 740,000 pieces of data leaked.

On July 29th, British media revealed that the UK Department for Education (DfE) and a police database were targeted in a cyber attack, resulting in the leakage of over 740,000 records. The Department for Education has confirmed the breach and stated that they are closely collaborating with the National Cyber Security Centre and the National Crime Agency.

An unknown hacker group called “ExfilSquad” has claimed responsibility for the incident and has released some data samples on their “leak site”.

Screenshots obtained by The Guardian show that the hackers are demanding an undisclosed ransom amount from the Department for Education and other related entities. They have threatened to release all the data if the ransom is not paid, potentially leading the government to face significant costs in data breach lawsuits.

The hacker website indicates that over 600,000 leaked records are from the Department for Education’s online helpdesk, including full names, emails, phone numbers, and job titles of parents, educators, and school administrators.

Another set of data, albeit in smaller quantity but similar in nature, has leaked from the “Turing Scheme” portal, which manages student exchanges for studying abroad.

The Department for Education emphasizes that they have taken “swift action” to control the situation and that the impacted information is limited to contact details related to individuals and organizations, with no other data being compromised. There is currently no evidence that the hackers used ransomware to lock systems.

In response to the cyber attack, the UK government is conducting a joint investigation with the National Cyber Security Centre (NCSC) and the National Crime Agency (NCA). They have reported the incident to the data regulatory authority, the Information Commissioner’s Office (ICO).

Apart from the education sector, hackers have also breached the “Police National Legal Database” (PNLD), which provides legal assistance to various police departments in the UK. The hackers claim to have stolen approximately 135,000 records, including names, job positions, work emails of police and criminal justice personnel, and even passwords used to access the website.

Additionally, some personal data of individuals who have previously submitted queries to the “Ask the Police” service has been compromised.

The database is hosted by the West Yorkshire Police and is accessible to police units across England and Wales. The police responsible for hosting the database clarified that it does not store confidential information such as victims, witnesses, or offenders, and the initial risk assessment indicates a low level of risk.

However, Jake Moore, a global cybersecurity consultant at a top European cybersecurity company ESET, warns that government agencies often have weak defenses due to inadequate budgets, making them easy targets for cybercriminals.

He cautions that such hacker intrusions are not isolated incidents, citing numerous similar attacks on government agencies in the past that have significantly impacted government operations. Thus, Moore emphasizes that the UK government must learn from past mistakes.

According to the NCSC’s 2025 annual review report, the number of cyber attacks classified as “of national significance” has significantly increased from 89 cases in the previous year to 204 cases, with 18 incidents classified as “of highly significant.”