1 month ago

UK Education Department Hack Exposes 607,000 Records of Staff

UK Education Department Hack Exposes 607,000 Records of Staff
UK education department hack exposes 607,000 records of school leaders, university staff · firstpost.com

A group of hackers broke into the UK Department for Education’s computer system and stole information about 607,000 people, like school leaders and university staff.

They got names, job titles, emails, and phone numbers.

The hackers said they used a group called ExfilSquad.

The department said the data is not easy to combine, so the risk is low.

They are fixing the system and working with security agencies to investigate.

Key facts

Affected records
607,000
Data exposed
names, job titles, email addresses, phone numbers
Targeted systems
Help desk, Turing Scheme portal
Responsible group
ExfilSquad
Investigating agencies
Information Commissioner’s Office, National Crime Agency, National Cyber Security Centre
Risk level
Low
Response actions
Repair portals, switch telephone communications

Quotes

Jake Moore

Cybersecurity adviser at European security firm ESET

“"Government agencies often lack proper funding and consequently may not have the best protection for their systems, making them soft targets for cybercriminals. With weaker security, government agencies and departments can also get unintentionally caught up in a net of ransomware attacks when other companies are targeted."”
firstpost.com
“"When information like this is stolen, criminals can still do a lot by piecing together a data jigsaw and even creating convincing follow up phishing emails to lure people into clicking into malicious sites. It’s best to remain vigilant to any unsolicited communication."”
firstpost.com

Department for Education spokesperson

Official representative of the UK Department for Education

“"We have robust processes in place to protect information and took swift action to contain this incident. The information involved is limited to customer service contact details relating to individuals and organisations. No other data has been accessed."”
firstpost.com

Sources

Related news