Infosecurity

Cyber Extortionists Hit UK Department for Education, Claim 600,000 Data Lines

Published

on

What Happened?

Cybercriminals are trying to squeeze money out of Britain’s Department for Education (DfE) after breaking into two of its portals. The group behind the attack, calling itself ExfilSquad, claims to have walked away with more than 600,000 pieces of data — names, email addresses, phone numbers.

But here’s the catch: the DfE says that number refers to lines of data, not individuals. So the actual number of people affected could be far smaller. A spokesperson stressed that the risk to individuals is not considered high.

Which Systems Were Hit?

Two portals took the hit: the DfE Help Desk Self-Service Portal and the Turing Scheme Portal. The Turing Scheme, for those unfamiliar, is the UK government’s global exchange program — it funds students and learners to study and work abroad.

ExfilSquad is demanding a ransom in exchange for not releasing the stolen information. Notably, there’s no claim that they encrypted any systems. This is pure extortion — steal, threaten, collect.

Police Data Also Compromised

Separately, the Police National Legal Database (PNLD) was breached, with 135,000 pieces of data potentially identifying the names, forces, and work email addresses of police officers and others in the criminal justice system. The good news? It doesn’t contain protected information from investigations or witnesses.

The Home Office declined to comment. The National Cyber Security Centre, however, said they are “supporting law enforcement colleagues in response to an incident affecting the Police National Legal Database.”

UK Government’s Stance on Ransom Payments

Britain’s government doesn’t pay ransoms. Period. And it’s moving to make that official for the public sector and critical national infrastructure. Last year, it advanced plans to make it illegal for these entities to make ransomware payments — a move designed to choke off the funding that fuels this criminal industry.

That policy is not yet law, but the direction is clear: if you’re a public body in the UK, paying up could soon be a crime.

Ransomware Attacks on Government Are Declining

Here’s a silver lining. According to data from Britain’s privacy regulator, ransomware attacks on central government have dwindled. After 11 incidents in 2023, only four were reported in the two years that followed. More recent data isn’t available yet, but the trend is promising.

Still, this latest breach shows the threat hasn’t disappeared. It’s evolved.

DfE’s Response

A DfE spokesperson said: “We have robust processes in place to protect information and took swift action to contain this incident. The information involved is limited to customer service contact details relating to individuals and organisations. No other data has been accessed.”

That’s the official line. Whether ExfilSquad actually has what they claim — and whether they’ll follow through on their threat — remains to be seen.

For those following cyber crime trends, this is a familiar pattern: steal data, demand payment, threaten exposure. The UK’s refusal to negotiate is a strong deterrent, but it also means the criminals might follow through on their threats. That’s the ugly calculus of ransomware in 2026.

If you’re involved in the education sector or the criminal justice system in the UK, it’s worth checking whether your contact details might be in the wrong hands. And if you’re a policymaker, this is another reminder that the fight against ransomware is far from over.

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending

Exit mobile version