Department for Education suffers data breach – Computer Weekly

Shawn – stock.adobe.com
The Department for Education (DfE) has fallen victim to a major data breach after a threat actor known only as ExfilSquad targeted an internal helpdesk used by school and university staff, and local authorities, in a social engineering attack.
According to The Times, which was first to report on the leak, the attackers made off with over 600,000 records comprising personally identifiable information (PII) – including full names, email addresses and phone numbers – of government and university staff, and senior school officials such as headteachers.
The newspaper revealed a number of dark web postings made by individuals purporting to represent ExfilSquad, which laid claim to the attack, and has verified the authenticity of some of the data. Little is known about the ExfilSquad group, but in recent days it appears to have also claimed responsibility for an alleged, unconfirmed breach at Microsoft.
Computer Weekly understands the DoE has pulled a number of systems offline, and is in dialogue with the Information Commissioner’s Office (ICO), the National Crime Agency (NCA), and the National Cyber Security Centre (NCSC).
A DfE spokesperson said: “We have robust processes in place to protect information and took swift action to contain this incident.
“The information involved is limited to customer service contact details relating to individuals and organisations. No other data has been accessed. We continue to work closely with the National Cyber Security Centre and the National Crime Agency, and remain in contact with those affected.”
Commenting on the attack. Jamie Moles, senior technical manager at ExtraHop, said: “Seeing over 600,000 records from the Department for Education leaked on the dark web isn’t just frustrating – it’s entirely preventable. Educational institutions and government bodies hold high-value data and underpin critical public infrastructure, yet they continue to be treated by attackers as soft targets. Exposing headteachers, university leaders, and officials to targeted phishing and identity theft is a severe operational vulnerability.
“To stop this cycle, public sector organisations must secure their service desks, third-party supply chains, and external tools before bad actors exploit them. Calling in the National Cyber Security Centre (NCSC) and the NCA after a beach is damage control, not a security strategy. 
Moles added: “Institutions need to work hand-in-hand with the NCSC proactively – embedding their Active Cyber Defence tools, sharing real-time threat intelligence, and conducting rigorous resilience exercises long before a breach happens. Upfront cyber investment and the ability to actually see activity in real-time will remain the safer and more effective option than reactive disaster recovery, regulatory penalties, and a total loss of public trust.”
Besides any attempt to extort the DfE for the safe return or deletion of the stolen data – note that the use of ransomware has not been confirmed at the time of going to press – the immediate danger in an incident such as this one is the use of the data in follow-on cyber attacks by other gangs that target individuals whose data was compromised.
Jake Moore, global cyber security advisor at ESET, said: “Criminals can still do a lot by piecing together a data jigsaw and even creating convincing follow up phishing emails to lure people into clicking into malicious sites. It’s best to remain vigilant to any unsolicited communication.”
June’s AI Executive Order promotes voluntary engagement between AI developers and the federal government, emphasizing vendor …
Quantum computing is still in its early stages, but CIOs in some industries should pay attention now. Learn where the technology …
AI slopification in business processes creates a costly debt cycle of rework, damaged customer trust and lost productivity that …
With so many services requiring access to sensitive data, encryption alone is not enough. Data obfuscation has evolved into a …
A security data lake gives organizations a centralized repository of security information, but it can pose governance and …
IAM is more crucial than ever in the AI era. To better control who — and what — is accessing systems and data, security teams …
NetScout boosts its attack mitigation capacity to 33 Tbps and plans to strengthen integration between its on-premises and …
Intelligent technologies that include predictive analytics and intent-based networking are reshaping how enterprises oversee …
Digital transformation promises faster decision- making and greater UX. However, a lack of visibility into the network can hinder…
As AI needs rise and cloud costs escalate, organizations are reassessing colocation, adopting a balanced approach that …
IBM is looking to close what its CEO is calling “delayed sales” and eyeing a quantum future. While infrastructure and mainframe …
Organizations are encountering a talent shortage in data centers as demand for AI-driven infrastructure grows. Explore insights …
AI initiatives are driving demand for curated, controlled data. Leaders must move beyond capacity planning and build the …
Agentic AI demands that CDOs move beyond cataloging to curating the context AI systems retrieve, creating a new accountability …
The vendor’s Web Search Agents autonomously learn domain-specific use cases to help enterprises collect contextually relevant …
©2026 TechTarget, Inc. d/b/a Informa TechTarget. All Rights Reserved.

Privacy Policy
Cookie Preferences
Do Not Sell or Share My Personal Information

source
This is a newsfeed from leading technology publications. No additional editorial review has been performed before posting.

Leave a Reply