ComputerWeekly

Department for Education suffers data breach


The Department for Education (DfE) has fallen victim to a major data breach after a threat actor known only as ExfilSquad targeted an internal helpdesk used by school and university staff, and local authorities, in a social engineering attack.

According to The Times, which was first to report on the leak, the attackers made off with over 600,000 records comprising personally identifiable information (PII) – including full names, email addresses and phone numbers – of government and university staff, and senior school officials such as headteachers.

The newspaper revealed a number of dark web postings made by individuals purporting to represent ExfilSquad, which laid claim to the attack, and has verified the authenticity of some of the data. Little is known about the ExfilSquad group, but in recent days it appears to have also claimed responsibility for an alleged, unconfirmed breach at Microsoft.

Computer Weekly understands the DoE has pulled a number of systems offline, and is in dialogue with the Information Commissioner’s Office (ICO), the National Crime Agency (NCA), and the National Cyber Security Centre (NCSC).

A DfE spokesperson said: “We have robust processes in place to protect information and took swift action to contain this incident.

“The information involved is limited to customer service contact details relating to individuals and organisations. No other data has been accessed. We continue to work closely with the National Cyber Security Centre and the National Crime Agency, and remain in contact with those affected.”

Commenting on the attack. Jamie Moles, senior technical manager at ExtraHop, said: “Seeing over 600,000 records from the Department for Education leaked on the dark web isn’t just frustrating – it’s entirely preventable. Educational institutions and government bodies hold high-value data and underpin critical public infrastructure, yet they continue to be treated by attackers as soft targets. Exposing headteachers, university leaders, and officials to targeted phishing and identity theft is a severe operational vulnerability.

“To stop this cycle, public sector organisations must secure their service desks, third-party supply chains, and external tools before bad actors exploit them. Calling in the National Cyber Security Centre (NCSC) and the NCA after a beach is damage control, not a security strategy. 

Moles added: “Institutions need to work hand-in-hand with the NCSC proactively – embedding their Active Cyber Defence tools, sharing real-time threat intelligence, and conducting rigorous resilience exercises long before a breach happens. Upfront cyber investment and the ability to actually see activity in real-time will remain the safer and more effective option than reactive disaster recovery, regulatory penalties, and a total loss of public trust.”

Unsolicited communications

Besides any attempt to extort the DfE for the safe return or deletion of the stolen data – note that the use of ransomware has not been confirmed at the time of going to press – the immediate danger in an incident such as this one is the use of the data in follow-on cyber attacks by other gangs that target individuals whose data was compromised.

Jake Moore, global cyber security advisor at ESET, said: “Criminals can still do a lot by piecing together a data jigsaw and even creating convincing follow up phishing emails to lure people into clicking into malicious sites. It’s best to remain vigilant to any unsolicited communication.”



Source link