The Department for Education (DfE) has fallen victim to a major data breach after a threat actor known only as ExfilSquad targeted an internal helpdesk used by school and university staff, and local authorities, in a social engineering attack.
According to The Times, which was first to report on the leak, the attackers made off with more than 600,000 records comprising personally identifiable information (PII) – including full names, email addresses and phone numbers – of government and university staff, and senior school officials such as headteachers.
The newspaper revealed a number of dark web postings made by individuals purporting to represent ExfilSquad, which laid claim to the attack, and has verified the authenticity of some of the data. Little is known about the ExfilSquad group, but in recent days it appears to have also claimed responsibility for an alleged, unconfirmed breach at Microsoft.
Computer Weekly understands the DoE has pulled several systems offline, and is in dialogue with the Information Commissioner’s Office (ICO), the National Crime Agency (NCA), and the National Cyber Security Centre (NCSC).
A DfE spokesperson said: “We have robust processes in place to protect information and took swift action to contain this incident. The information involved is limited to customer service contact details relating to individuals and organisations. No other data has been accessed. We continue to work closely with the National Cyber Security Centre and the National Crime Agency, and remain in contact with those affected.”
Criminals can do a lot by piecing together a data jigsaw and even creating convincing follow-up phishing emails to lure people into clicking into malicious sites. It’s best to remain vigilant to any unsolicited communication Jake Moore, ESET
Commenting on the attack. Jamie Moles, senior technical manager at ExtraHop, said: “Seeing over 600,000 records from the Department for Education leaked on the dark web isn’t just frustrating – it’s entirely preventable. Educational institutions and government bodies hold high-value data and underpin critical public infrastructure, yet they continue to be treated by attackers as soft targets. Exposing headteachers, university leaders and officials to targeted phishing and identity theft is a severe operational vulnerability.
“To stop this cycle, public sector organisations must secure their service desks, third-party supply chains and external tools before bad actors exploit them. Calling in the NCSC and the NCA after a breach is damage control, not a security strategy.”
Moles added: “Institutions need to work hand-in-hand with the NCSC proactively – embedding their Active Cyber Defence tools, sharing real-time threat intelligence, and conducting rigorous resilience exercises long before a breach happens. Upfront cyber investment and the ability to actually see activity in real time will remain the safer and more effective option than reactive disaster recovery, regulatory penalties, and a total loss of public trust.”
Unsolicited communications
Besides any attempt to extort the DfE for the safe return or deletion of the stolen data – note that the use of ransomware has not been confirmed at the time of going to press – the immediate danger in an incident such as this one is the use of the data in follow-on cyber attacks by other gangs that target individuals whose data has been compromised.
“Criminals can still do a lot by piecing together a data jigsaw and even creating convincing follow-up phishing emails to lure people into clicking into malicious sites,” said Jake Moore, global cyber security advisor at ESET. “It’s best to remain vigilant to any unsolicited communication.”
Why this attack method is dangerous BMCs sit a layer below that which many security products monitor, on shared out-of-band management networks where administrative credentials are often reused. Thus, malicious changes made to BMCs or other platform hardware are able to survive OS reinstalls, disk replacements, and standard incident response procedures, Katchinskiy noted. The risk…
Even tiny drives, like a 120GB SATA SSD, can come in handy. After all, if the drive is working, there’s nothing stopping you from giving it a more or less useful job. But what if it’s fully, 100% dead? Kaput, no-go, knocked out cold? Well, that changes things. But before you take it to your…
“Antares outputs a ranked list of source files likely to contain a relevant vulnerability, along with the terminal exploration trace that led to that result,” Cisco Foundation AI Chief Scientist Amin Karbasi wrote in a blog post, adding that the models are not meant to replace the broader application security toolchain: Human analysts or downstream…
Article Brief Key Takeaways 5 Points30s Read 01One model, four outputs–FLUX 3 generates images, video with native audio, and robot action predictions from a single system Black Forest Labs calls Self Flow. 02Video specs–Clips run up to 20 seconds with native audio, built from text, a still image, or existing footage. 03The robotics tell–The action…
Alibaba’s Tongyi Lab has released Qwen-Audio-3.0-TTS, a production-oriented text-to-speech (TTS) system. The model ships in two variants from the same lineage. Flash targets real-time interaction. Plus targets high-quality generation. Both are delivered as hosted models through Alibaba Cloud Model Studio, not as downloadable weights. The release focuses on four things developers hit in production: broader…