1 month ago
UK Education Department Hack Exposes 607,000 Records of Staff
A group of hackers broke into the UK Department for Education’s computer system and stole information about 607,000 people, like school leaders and university staff.
They got names, job titles, emails, and phone numbers.
The hackers said they used a group called ExfilSquad.
The department said the data is not easy to combine, so the risk is low.
They are fixing the system and working with security agencies to investigate.
Hackers breached the UK Department for Education, exposing about 607,000 records.
Exposed data included names, job titles, emails, and phone numbers of school leaders, university staff, and officials.
Attack targeted the help desk and Turing Scheme portal, claimed by the cybercriminal group ExfilSquad.
The department says the risk is low because the data sets cannot be easily linked; investigations involve the ICO, NCA, and NCSC.
Portals were repaired, telephone communications were switched, and the department confirmed no other data was accessed.
- Who
- Hackers (ExfilSquad) and UK Department for Education staff
- What
- Breach exposing 607,000 records of personal data
- Where
- United Kingdom, UK Department for Education
- When
- Why
- To obtain personal data of education sector staff
Key facts
- Affected records
- 607,000
- Data exposed
- names, job titles, email addresses, phone numbers
- Targeted systems
- Help desk, Turing Scheme portal
- Responsible group
- ExfilSquad
- Investigating agencies
- Information Commissioner’s Office, National Crime Agency, National Cyber Security Centre
- Risk level
- Low
- Response actions
- Repair portals, switch telephone communications
Quotes
Jake Moore
Cybersecurity adviser at European security firm ESET
“"Government agencies often lack proper funding and consequently may not have the best protection for their systems, making them soft targets for cybercriminals. With weaker security, government agencies and departments can also get unintentionally caught up in a net of ransomware attacks when other companies are targeted."”
firstpost.com
“"When information like this is stolen, criminals can still do a lot by piecing together a data jigsaw and even creating convincing follow up phishing emails to lure people into clicking into malicious sites. It’s best to remain vigilant to any unsolicited communication."”
firstpost.com
Department for Education spokesperson
Official representative of the UK Department for Education
“"We have robust processes in place to protect information and took swift action to contain this incident. The information involved is limited to customer service contact details relating to individuals and organisations. No other data has been accessed."”
firstpost.com









