Decoding the world of cybersecurity

UK education and police support data stolen

Hackers have claimed data from Department for Education and Police National Legal Database-linked systems, exposing public-sector contact records and staff details.

UK education and police support data stolen
Summary
  • More than 740,000 reported data items were taken from Department for Education and Police National Legal Database-linked systems.
  • Reported exposed data includes names, work emails, phone numbers, job titles, organisations, and some Ask the Police contact details.
  • The incident places help desk portals, staff targeting, password reuse, and public-sector service data under scrutiny.

The Department for Education and the Police National Legal Database have been targeted in a cyber incident in which hackers claim to have stolen more than 740,000 pieces of data.

Reportedly exposed material includes just over 600,000 lines of data from a DfE help desk portal, a smaller package from the department’s Turing portal, and about 135,000 pieces of data connected to the Police National Legal Database. The data is said to include names, work email addresses, phone numbers, job titles, organisations, and force details.

The Police National Legal Database provides legal assistance to UK police forces and is hosted by West Yorkshire Police. Reporting indicates that some names and email addresses of members of the public who submitted questions through the Ask the Police service were also taken. PNLD has said the database does not hold confidential victim, witness, or offender information.

The Department for Education said “swift action” had been taken to contain the incident. It also said: “The information involved is limited to customer service contact details relating to individuals and organisations. No other data has been accessed.”

Those statements place boundaries around the known exposure. The incident is not currently described as a compromise of the Police National Computer or Police National Database, and there is no public evidence that direct information about officers in sensitive postings was exposed. The reported theft of passwords used to access the PNLD site adds a separate risk route, particularly if any credentials were reused on other systems.

The public-sector exposure is still material. Contact data can help attackers build convincing phishing, impersonation, credential theft, and social engineering campaigns. Names, roles, force affiliations, school contacts, university details, and work email addresses make it easier to target people with messages that appear administratively plausible.

Help desk and service portals are often overlooked repositories of organisational data. They can collect contact records, attachments, routing notes, free-text requests, and operational context over time. Even where individual fields are low sensitivity, the combined dataset can show who works where, who supports which process, and how public bodies interact with specific services.

The alleged attacker group, calling itself ExfilSquad, reportedly posted samples and demanded payment from affected organisations. The group’s identity, capability, and access route remain unconfirmed. The government is working with the National Cyber Security Centre and the National Crime Agency, and the DfE and PNLD have reported the incident to the Information Commissioner’s Office.

The immediate operational work will be practical: confirm the data set, assess credential exposure, warn affected staff and service users, monitor for targeted follow-on campaigns, and preserve evidence for regulatory and criminal investigations. Public bodies also need to understand whether service-desk platforms are holding more information than necessary and whether retention controls reflect the risk created by aggregated records.

The incident shows how public-sector risk can emerge from systems built for support rather than policy delivery. A help desk can become an exposure point when contact data, passwords, and organisational context are concentrated without controls matching their cumulative value.

×