Hackers steal 600,000+ data lines from UK education department and police database
Hackers steal 600k+ data lines from UK education dept and police

Hackers have stolen more than 740,000 pieces of data from the UK Department for Education (DfE) and a police legal database, exposing personal details of government officials, school leaders, university staff, police officers, and members of the public.

DfE breach details

Just over 600,000 lines of data were taken from the DfE's help-desk portal, including parent and staff contacts with full names, email addresses, phone numbers, and job titles, according to a leak site set up by the hackers. A smaller package of similar data was stolen from the department's Turing portal, which manages a scheme for students studying abroad.

Police national legal database compromise

The hackers also breached the Police National Legal Database (PNLD), which provides legal assistance to UK police forces, claiming to have taken 135,000 pieces of data. The PNLD confirmed the stolen information includes names of police officers and criminal justice workers, their force or organisation, and work email addresses. Some names and addresses of members of the public who had submitted questions to the Ask the Police service were also taken. The database does not hold confidential victim, witness, or offender information.

Wide Pickt banner — collaborative shopping lists app for Telegram, phone mockup with grocery list

While embarrassing, the breach of the police legal database is not considered serious. The hack also includes theft of passwords used to access the site.

ExfilSquad gang demands payment

A previously unknown hacking gang calling itself ExfilSquad claimed responsibility and posted data samples on its leak site, a typical tactic for cybercriminals seeking ransom. Screen grabs seen by the Guardian show messages demanding payment from the DfE and PNLD in exchange for not posting all data. The gang stated: "The payment we request of you is simply a rounding error compared to the litigation costs of your data leaking. Be smart and just pay." The message is directed at 14 hacking victims, including a UK university contacted by the Guardian.

Expert assessment and government response

Sophos, a cybersecurity company, said the data samples appeared legitimate. An X account apparently belonging to the group has been suspended. The DfE has not seen evidence of ransomware deployment. A senior source briefed on the PNLD leak said: "The risk is low. The question is, if you use your password for the PNLD, do you use it for more sensitive systems?" The source added it was "early days in our understanding of what has happened." The government is working with the National Cyber Security Centre and the National Crime Agency. The DfE and PNLD have reported the incident to the Information Commissioner's Office. The DfE said swift action was taken, and the information involved is limited to customer service contact details.

Pickt after-article banner — collaborative shopping lists app with family illustration