TechNewsReel
Live

Hackers Steal 607,000 Professional Records from UK Department for Education

A breach of the DfE's help desk and Turing Scheme portal has exposed the contact details of thousands of educators and government officials.

TechNewsReel Newsroom · August 2, 2026

A cybercriminal group known as ExfilSquad has breached the UK Department for Education (DfE) and police systems, stealing hundreds of thousands of professional records. The attack exposes the contact information of high-ranking educators and government officials, creating a significant security vulnerability for the UK's public sector.

According to reports from f1tym1 and IBTimes UK, the hackers targeted the DfE's online customer help desk—specifically the Self-Service Portal—and the Turing Scheme portal. Approximately 607,000 records were exfiltrated from these systems. The stolen data includes names, job titles, work email addresses, and telephone numbers. The breach also extended to police systems, specifically targeting the Police National Legal Database (PNLD), with some reports indicating the total number of compromised records across both sectors reaches roughly 740,000.

The Education Sector Under Fire

This incident occurs amid a broader trend of escalating cyber threats targeting the UK's educational infrastructure. A recent government survey highlighted the fragility of these systems, revealing that more than half of all schools in the country reported at least one cyber incident within the previous 12 months. The targeting of the Turing Scheme portal—a program designed to support students and staff in studying or researching abroad—suggests that attackers are identifying specific, high-traffic portals as points of entry into wider government networks.

The Risk of Spear-Phishing

While the stolen data consists of professional rather than private personal information, cybersecurity experts warn that the breach is far from harmless. Professional contact details are highly prized for "spear-phishing" campaigns, where attackers use specific job titles and names to craft convincing, fraudulent emails. By building detailed profiles of head teachers, university staff, and government officials, ExfilSquad or other threat actors can impersonate trusted colleagues to trick victims into revealing passwords or installing malware. This technique is often the first step in a larger operation to gain deep access to sensitive government or police networks.

Next Steps for Investigation

ExfilSquad has already published the stolen data online, making the information available for other criminal entities to exploit. While the core facts of the breach and the volume of stolen records are confirmed, the full extent of the police database compromise remains a primary point of concern. Investigators will likely focus on whether the attackers gained deeper access to the Police National Legal Database or if the breach was limited to the contact directories of the personnel managing those systems.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.