UK Education Department confirms breach as mystery hacker gang leaks 600K records
The gang's ambitious first victim list – claiming 15 major organizations, including Microsoft – raises more questions than answers.

Image by Brookgardener | Shutterstock
- Hackers claim they breached two UK education portals used by parents, schools, and international programs.
- A second victim – the UK Police National Legal Database – has been confirmed, potentially exposing police officer contact details.
- A new extortion group called ExfilSquad claimed both breaches and more than a dozen other victims – but not all of its claims are holding up.
A previously unknown extortion gang known as ExfilSquad has hit the ground running -- claiming several major breaches this week, including the UK Department for Education (DfE), allegedly leaking 600,000 sensitive records stolen from the agency’s online portal.
The DfE confirmed the incident on Tuesday after the newbie gang claimed to have dumped the hundreds of thousands of records after extracting them from the department’s Help and Turing Scheme portals.
The DfE is a government agency responsible for child protection, child services, education, and apprenticeships in England.
A new hacker group – ExfilSquad – says the stolen data includes the names, email addresses, phone numbers, and job titles of parents and education staff.
ExfilSquad also claimed responsibility for an attack on the UK Police National Legal Database (PNLD), allegedly exposing the contact information of police officers, criminal justice workers, and some members of the public.
The UK Police also confirmed the incident on Tuesday, according to The Guardian.
Parents and school staff caught in DfE breach
According to the gang's leak site, the DfE dataset contains approximately 600,000 Help Portal records and another 7,000 records from the UK's Turing Scheme portal, which funds international education exchanges.
The dataset is said to expose full names, email addresses, phone numbers, and job titles belonging to parents and education staff.
ExfilSquad claims to have stolen 440 MB of uncompressed data in total – a relatively small amount - while also providing a torrent link to the alleged cache.
The Department for Education said it had taken “swift action” to contain the breach, The Guardian reported.
“The information involved is limited to customer service contact details relating to individuals and organisations. No other data has been accessed,”the DfE said.
Education officials have notified the Information Commissioner's Office and are working with the National Cyber Security Centre and the National Crime Agency as the investigation continues.
The DfE has not publicly confirmed the number of impacted or verified how much data was accessed.
Expert warns education sector remains a top target
Frank van Oeveren, associate director for Global Threat Intelligence at NCC Group, says even though the DfE says that the stolen data is limited to contact details, “the exposure linked to school leaders, university staff and government personnel should not be underestimated.”
“Information such as names, job titles, telephone numbers and email addresses can be highly valuable to threat actors, enabling more convincing phishing, social engineering and follow-on attacks,” van Oeveren says.
The threat intel director also explains that education remains one of the most consistently targeted sectors, noting that recent NCC Group analysis shows more than 100 ransomware attacks against educational institutions globally in the first 5 months of 2026 alone.
One of those attacks includes the ShinyHunters May breach of the Canvas learning management systems (LMS), an e-learning platform used by nearly 9,000 schools worldwide.
Considered by far one of the largest cyberattacks ever involving the educational sector, ShinyHunters – who knocked the system offline during finals week – threatened to leak an alleged 3.65TB of stolen data, including billions of personal messages tied to more than 275 million students and faculty members.
In the end, Canvas owner Instructure admitted to paying the hackers an undisclosed amount to keep the data from being exposed.
“Threat groups continue to view educational organizations as attractive targets due to the volume of personal data they hold, the complexity of their technology estates and the operational pressure to maintain services,”van Oeveren said.
Police passwords, contact data allegedly stolen
The UK Police National Legal Database also confirmed that data was taken from its systems.
The hacker group claims to have 1.9 GB of uncompressed PNLD data in its possession, exposing 135k law enforcement contact records, including “first/last name, email, police force area, etc.,” the group wrote.
Researchers told The Guardian the information also includes work email addresses, police force or organization, and similar contact details of police officers and criminal justice workers.
Additionally, the data was said to include some names and email addresses of members of the public who submitted questions through the "Ask the Police" service.
The PNLD stressed the stolen information did not contain “confidential victim, witness, or offender information.
”The database is hosted by West Yorkshire police and is open for forces across England and Wales to view," The Guardian reported.
Passwords used to access the site were also apparently accessed by the attackers, although one senior official dismissed the impact, claiming the “risk was low” for gaining access to more sensitive systems.
New extortion gang claims 15 victims
The never-before-heard-of gang appeared seemingly out of nowhere this week, apparently adding a total of 15 victims all at once on its dark leak site – quite a large debut for a newbie extortion group.
Alongside the two confirmed UK breaches, ExfilSquad also claimed to have hacked more than a dozen major organizations, including Microsoft, Frontier Airlines, Allstate, the City of Houston, and the City of Atlanta.
Cybernews believes some of the victim data could be repackaged from previously reported breaches.
Microsoft has not acknowledged any recent cyber incidents, and most of the other claims have not been independently verified.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
The group, which has given all the victims until August 5th to make contact, claims to have stolen 130 GB of uncompressed data from Microsoft, including contact information from the company’s internal CRM records.
Providing contact info for Microsoft CEO Satya Nadella and other C-suite execs as proof of its handiwork, ExfilSquad claims to have stolen 8 million records containing PII, authentication data, password hashes, corporate account information, access permissions, and more.
Check if your data has been leaked