UK Department for Education Hit by Data Breach, ExfilSquad Claims Extortion
Britain's Department for Education (DfE) is facing extortion demands after cybercriminals claimed to have stolen over 600,000 data records, including names and contact information.
Cybercriminals are attempting to extort Britain’s Department for Education (DfE) after compromising what the criminals said was more than 600,000 pieces of data allegedly including names, email addresses and phone numbers. A spokesperson for the DfE clarified that the number refers to lines of data, rather than the count of individuals affected, and stated that two portals used by the department—the DfE Help Desk Self-Service Portal and the Turing Scheme Portal—were impacted. The department indicated that the risk to individuals is not considered high.
The breach was claimed by an extortion group identifying themselves as ExfilSquad, who are reportedly demanding a ransom in exchange for not releasing the stolen information. Notably, there has been no claim that the hackers encrypted the compromised systems, suggesting a data-theft-only operation rather than a traditional ransomware attack.
In a separate but related incident, the Police National Legal Database (PNLD) was also impacted, with approximately 135,000 pieces of data potentially identifying the names, police forces, and work email addresses of officers and other criminal justice system personnel. The Home Office has declined to comment on the PNLD breach, while the National Cyber Security Centre confirmed they are "supporting law enforcement colleagues in response to an incident affecting the Police National Legal Database."
The British government maintains a policy of not making ransom payments. Furthermore, the government has been progressing plans to make it illegal for public sector entities and critical national infrastructure organizations to pay ransoms in response to ransomware attacks, although this is not yet law. This stance reflects a broader strategy to stifle the ransomware industry.
Data from Britain's privacy regulator indicates a decrease in ransomware attacks on central government entities in recent years. Following 11 reported incidents in 2023, only four were reported in the subsequent two years, though more recent data is not yet available.
A spokesperson for the Department for Education emphasized that the department "has robust processes in place to protect information and took swift action to contain this incident." They reiterated that the compromised data is limited to customer service contact details and that no other data has been accessed.
This incident highlights the persistent threat of data extortion, even when encryption is not involved. The targeting of government departments underscores the value of public sector data and the sophisticated tactics employed by cybercriminal groups like ExfilSquad.
The DfE's swift response and containment efforts, coupled with the government's firm stance against ransom payments, are critical in managing the fallout from such breaches and deterring future attacks.