
Hackers have reportedly breached a system operated by the United Kingdom’s Department for Education, exposing contact information tied to approximately 607,000 records belonging to school leaders, university staff and government officials.
The compromised data reportedly includes names, job titles, email addresses and phone numbers of individuals who had contacted the department. The Times reported that the attack targeted the DfE’s help desk, which fields inquiries from schools and local authorities, as well as the Turing Scheme portal, which educational institutions use to manage students studying abroad.
A group calling itself ExfilSquad claimed responsibility for the breach in posts on the dark web, according to The Times, and is reportedly seeking a ransom payment in exchange for not releasing the stolen information. There is no indication that the attackers encrypted any of the department’s systems.
A DfE spokesperson said the incident was contained quickly and that only limited customer service contact details tied to individuals and organizations were affected, adding that no other data had been accessed. The department has notified the Information Commissioner’s Office and is working with the National Crime Agency and the National Cyber Security Centre as the investigation continues. Officials are repairing the affected portals, and the department has temporarily rerouted its telephone communications as a precaution.
A separate spokesperson for the department said the 607,000 figure refers to individual lines of data rather than the number of people affected, and characterized the risk to those individuals as not high. Sources within the department told The Independent that the overall risk is considered low because the exposed information is split across separate datasets that are not easily linked together.
The Police National Legal Database was separately affected, with roughly 135,000 pieces of data potentially identifying the names, police forces and work email addresses of officers and other criminal justice personnel. That database does not contain protected information from active investigations or witnesses. The Home Office declined to comment on the incident, while a National Cyber Security Centre spokesperson said the agency is supporting law enforcement in responding to it.
British government policy prohibits paying ransoms, and legislation advanced last year would make it illegal for public sector bodies and critical national infrastructure organizations to make ransomware payments, though it has not yet become law. Data from Britain’s privacy regulator shows ransomware attacks on central government have declined in recent years, falling from 11 incidents in 2023 to four in each of the two years that followed, with more recent figures unavailable.
Jake Moore, a cybersecurity adviser at ESET, said government agencies often face weaker protections due to funding constraints, making them attractive targets for cybercriminals and vulnerable to being swept up in broader ransomware campaigns. He said the DfE breach is not an isolated case and pointed to a pattern of similar attacks on government and local government bodies that have caused prolonged disruption with wide-reaching effects. Moore added that stolen data of this kind can still be exploited by criminals piecing together information to craft convincing phishing attempts, and he urged vigilance against unsolicited communications.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543