The Department for Education data breach involved two departmental portals and a ransom demand from cyber extortionists who claim to have obtained more than 600,000 pieces of data, including names, email addresses and phone numbers.
A Department for Education spokesperson said the figure describes lines of data, rather than the number of people affected. The department said the DfE Help Desk Self-Service Portal and the Turing Scheme Portal were affected, and that it does not consider the risk to individuals to be high.
The group claiming responsibility calls itself ExfilSquad. It is demanding payment in exchange for not publishing the information. There has been no claim that the attackers encrypted the department’s systems, which means the incident described so far is data-theft extortion rather than a conventional ransomware lockout.
What data was taken from the Department for Education?
According to the Department for Education, the information involved was limited to customer service contact details tied to individuals and organizations. The department said no other data was accessed.
The practical risk depends on the contents of those contact records. Names, email addresses and phone numbers can be used for phishing, impersonation or nuisance targeting, even when the dataset does not contain passwords, financial records or highly sensitive personal files. The department’s position is that the available information does not point to a high risk for affected people.
The Department for Education said it had controls in place to protect information and acted quickly to contain the incident. Its spokesperson said: “We have robust processes in place to protect information and took swift action to contain this incident. The information involved is limited to customer service contact details relating to individuals and organisations. No other data has been accessed.”
What happened to the Police National Legal Database?
A separate breach affected the Police National Legal Database, known as PNLD. That incident involved 135,000 pieces of data that could potentially identify police officers and other criminal justice workers by name, force and work email address.
The PNLD dataset does not include protected material from investigations or witness information. The Home Office declined to comment on that breach. A spokesperson for the National Cyber Security Centre said the agency is “supporting law enforcement colleagues in response to an incident affecting the Police National Legal Database.”
The UK government’s standing policy is not to pay ransoms. Ministers have also moved toward tighter rules for the public sector and critical national infrastructure: last year, the government advanced plans that would make ransom payments illegal for those bodies in response to ransomware attacks, though that prohibition is not yet law.
Central government ransomware reports have fallen in the most recent figures available from Britain’s privacy regulator. There were 11 such incidents in 2023, followed by four reported across the next two years. More recent figures have not been published.
The extortion demand still leaves the government with a familiar problem: even when systems are not encrypted, stolen administrative data can become leverage. Publishing contact details is less damaging than dumping investigation files or credentials, but it still creates a cleanup bill for the public bodies and people whose details are now in criminal hands.
This story draws on original reporting from The Record.