Key points:
  • Hackers stole over 740,000 pieces of sensitive data from the Department for Education and police databases.
  • The stolen information includes names, email addresses, phone numbers, and job titles of parents, staff, university officials, and police officers.
  • ExfilSquad, an unknown hacking group, claimed responsibility for the breach and demanded payment in exchange for not releasing all the data.

Scope of the Cyber-Attack

The Department for Education (DfE) and a police database have been hit by a cyber-attack, resulting in the theft of more than 740,000 pieces of sensitive data. The breach has exposed details of parents, staff members, university officials, senior school leaders, and even some members of the public.

Cyber-Attack Steals Sensitive Data from UK Government and Police Databases
Cyber-Attack Steals Sensitive Data from UK Government and Police Databases

The DfE's help-desk portal was compromised first, with different sets of data taken that included personal contact information such as full names, email addresses, phone numbers, and job titles. The Turing portal used for managing international students also experienced a smaller breach involving similar sensitive data.

Hackers' Demands

ExfilSquad, an unknown hacking group, has publicly claimed responsibility for the attack and showcased samples of the stolen data on their leak website. According to reports, these hackers are seeking ransom payments from the DfE and the police national legal database (PNLD) in exchange for withholding all the data.

Screen grabs obtained by The Guardian reveal that ExfilSquad is demanding an unspecified payment from 14 hacking victims, including the DfE. They stated that only a small sample of data has been released publicly but threatened to post all of it if payments are not made. Their message emphasized that such a financial request would be minimal compared to the potential legal costs.

Implications and Security Measures

The breach of the police national legal database, which holds information related to police officers and individuals in criminal justice roles, was deemed less severe by security experts. The stolen data included passwords used for accessing the site but did not include sensitive operational details.

A senior source briefed on the PNLD leak noted that while the risk is low, it remains a concern if an individual uses the same password across multiple systems. The DfE has stated that swift action was taken to contain the incident and emphasized that no other data beyond customer service contact information was accessed.

The government acknowledged its involvement with the National Cyber Security Centre and the National Crime Agency in addressing the breach. Both the DfE and PNLD have reported the incident to the Information Commissioner's Office, the UK's data watchdog.

Source: The Guardian


Related post