ExfilSquad hackers expose 740,000 UK education and police records in dual extortion breach
- Marijan Hassan - Tech Journalist
- 12 minutes ago
- 2 min read
A cyberattack targeting two external-facing UK public sector systems has exposed over 740,000 data entries belonging to the Department for Education (DfE) and a major police database. The incident, which compromised contact details for headteachers, police officers, government officials, and members of the public, marks one of the largest public sector security failures in Britain this year.

The attack was claimed by a previously unknown extortion gang calling itself ExfilSquad. The threat actors published sample batches of the stolen files to a dark web leak site, threatening to release the entire repository unless an unspecified ransom payment is delivered.
DfE Help Desk and Turing Portal Compromised
The largest portion of the stolen data, comprising roughly 607,000 lines of information, was exfiltrated from two DfE platforms: the primary customer service help-desk portal and the Turing Scheme website, which handles study-abroad funding for UK students.
The stolen files contain names, job titles, work email addresses, and phone numbers of headteachers, university administrators, local authority officials, and parents who had contacted the department. DfE officials clarified that the 607,000 figure represents individual lines of data within separate databases rather than unique individuals, emphasizing that no financial records, student medical histories, or core IT infrastructure were breached.
Police National Legal Database Infiltrated
Simultaneously, ExfilSquad breached the Police National Legal Database (PNLD), an online resource hosted by West Yorkshire Police that provides legal assistance and operational guidance to police forces across England and Wales.
The gang exfiltrated roughly 135,000 records from the portal, including the names, force assignments, work email addresses, and encrypted site passwords of serving police officers and criminal justice personnel. The breach also exposed contact details of members of the public who had submitted inquiries through the "Ask the Police" online service.
Authorities confirmed that the PNLD does not hold confidential victim, witness, or active investigation data.
Elevated Risks of Targeted Spear-Phishing
The Department for Education and West Yorkshire Police have reported the incidents to the Information Commissioner’s Office (ICO) while working with the National Cyber Security Centre (NCSC) and the National Crime Agency (NCA) to investigate.
While government officials insist the risk to individuals is low because the exposed datasets are fragmented, cybersecurity experts warn the exfiltrated contact data presents immediate risks. Security analysts caution that attackers can easily harvest verified work emails, phone numbers, and job roles to launch highly convincing spear-phishing and social engineering campaigns targeting school leaders, universities, and police personnel across the UK.












