
A group calling themselves ExfilSquad has breached two UK government portals and is threatening to release more than 600,000 lines of data if a ransom is not paid. The affected systems are the Department for Education’s Help Desk Self-Service Portal and its Turing Scheme Portal, which handles applications for the UK’s international student placement program. The DfE confirmed the incident and said the data at risk is limited to customer service contact details — names, email addresses, and phone numbers — with the 600,000 figure referring to lines of data rather than individual people. The department said the risk to individuals is not considered high. In keeping with official policy, the UK government will not pay the ransom. ExfilSquad did not claim to have encrypted any systems, meaning this appears to be a purely extortion-focused data theft rather than a traditional ransomware deployment.
A separate but related breach also came to light: the Police National Legal Database (PNLD) was compromised, exposing up to 135,000 records that could identify the names, police forces, and work email addresses of officers and criminal justice workers. The PNLD does not hold protected information from active investigations or witness data. The National Cyber Security Centre confirmed it is supporting law enforcement in response to the PNLD incident; the Home Office declined to comment. Both breaches are developing, and neither affected organization has published an official breach notification for individuals at this time.
How to check if you’re affected
Affected products include the DfE Help Desk Self-Service Portal and the Turing Scheme Portal. If you have submitted a support request to the Department for Education Help Desk, or applied to the Turing Scheme as a student or participant, your contact details may be in the stolen data. If you are a police officer or criminal justice worker whose details are held in the Police National Legal Database, you should assume your work email and force affiliation are at risk. In both cases, watch for targeted phishing emails using your correct name and work contact details — even if the breach is limited to contact information, it gives attackers a credible hook.
