Hackers known as ExfilSquad have stolen over 740,000 records from the UK Department for Education (DfE) and a police legal database, including personal and professional contact details of thousands of individuals.

The breach, as reported by The Guardian, involves 607,000 lines of data from the DfE's help-desk portal and 135,000 records from the Police National Legal Database. The stolen data includes names, email addresses, phone numbers, and job titles of parents, staff, government officials, university workers, and police officers. Additionally, another 135,000 pieces of data were extracted from the police national legal database (PNLD).
The cybercriminals are demanding ransom from the DfE and other victims to prevent the full release of the data. "Be smart and just pay," the hackers wrote in a message seen by Sophos, a cybersecurity company that provided the screenshots to The Guardian, adding that the payment would be a "rounding error" compared to the financial cost of litigation.
The PNLD breach is being reported as "embarrassing," but not serious, as the database did not hold confidential victim, witness, or offender information. A senior source briefed on the police database leak noted that if users reused their PNLD passwords elsewhere, the impact could be more severe, and warned officials of using their PNLD password to access other sensitive systems. The UK government insists no sensitive systems were breached and that the DfE acted swiftly to contain the incident.
The DfE and PNLD have reported the breach to the Information Commissioner's Office, but the DfE hasn't detected any ransomware, and said that "swift action" was taken to contain the incident.

Frequently Asked Questions
TweakBot answers common questions about this news using TweakTown's own coverage from this page and related content from our archive. Tap a question to reveal the answer, or type your own below.
Which specific DfE systems or portals were compromised and which types of records from the DfE help-desk portal were exposed?
How many records were taken from the Police National Legal Database (PNLD) and what categories of police-related data were included?
Did the attackers deploy ransomware or encrypt any DfE or PNLD systems according to the article?
What steps did the DfE and PNLD claim they took to contain the breach, and have they reported the incident to regulators?
Have a question not listed here? Ask below and TweakBot will answer it.
"The information involved is limited to customer service contact details relating to individuals and organizations," it said. "No other data has been accessed," said the DfE






