Skip to content
Beveiligingsnieuws

Ransomware Extortion at UK Department for Education

ransomware data-ontvoering

Ransomware extortion has surfaced again in the UK after cybercriminals claimed they compromised systems tied to the Department for Education. According to the attackers, they obtained more than 600,000 pieces of data—allegedly including names, email addresses, and phone numbers—and then demanded payment in exchange for keeping the information private.

The Department for Education (DfE) responded that the reported number refers to lines of data, not necessarily the count of individuals affected. The department also stated that two specific portals were impacted and that the overall risk to people is not considered high.

What the attackers claimed in the extortion message

The breach was associated with a threat group calling itself ExfilSquad. In its claim, the group said it had taken data and demanded a ransom in return for not releasing the stolen information.

Importantly, there is no claim from the attackers that they encrypted the compromised systems. That matters because encryption-based incidents often indicate a different stage of disruption than data theft alone.

Which Department for Education portals were affected

DfE said the incident affected two portals used by the department:

  • DfE Help Desk Self-Service Portal
  • Turing Scheme Portal

DfE also provided context on the scope of what was accessed. A spokesperson said the information involved was limited to customer service contact details relating to individuals and organisations, and that the department took swift action to contain the incident.

In addition, the department said that no other data has been accessed. While the attackers’ numbers were large, DfE emphasised that the figure relates to data lines rather than a simple count of people.

Why the number “600,000” may not mean 600,000 people

For many ransomware extortion incidents, public reports often cite the amount of data taken. In this case, the department clarified that the “600,000+” figure represents data lines.

In practice, multiple lines can relate to the same individual—such as separate fields like name, email, and phone number. That means the headline total does not automatically translate into an equal number of uniquely impacted people.

Separate impact: Police National Legal Database

Alongside the Department for Education matter, the report also described a separate incident affecting the Police National Legal Database (PNLD). The compromised dataset was said to include potentially identifying information such as:

  • names
  • police forces
  • work email addresses

In this case, the figure cited was 135,000 pieces of data potentially identifying officers and others who work in the criminal justice system.

Officials also indicated what the database does not contain. The report states that the PNLD does not include protected information from investigations or witnesses. That distinction helps narrow concerns to contact-related data rather than sensitive case details.

Response from UK cyber security authorities

The Home Office reportedly declined to comment on the PNLD incident. However, a spokesperson for the National Cyber Security Centre (NCSC) said they were supporting law enforcement colleagues in response to an incident affecting the PNLD.

This type of involvement typically reflects the operational importance of national systems and the need to coordinate with policing and related agencies when personal or professional identifiers may be exposed.

Government policy: no ransom payments

As a matter of policy, the British government does not make ransom payments. That stance is particularly relevant in ransomware extortion cases, where attackers demand payment to prevent the release of stolen information.

While the current legal position is described in the report as policy-led and evolving, the government is also described as moving forward with plans to reduce ransomware profitability. The report says that, although it was not yet law at the time, the government aimed to make it illegal for public sector organisations—and organisations working within critical national infrastructure—to make a payment in response to ransomware attacks.

The overall intent is to suffocate the ransomware economy by limiting the financial incentives that extortion schemes rely on.

Ransomware activity in central government: reported decline

Ransomware extortion targeting central government systems has reportedly reduced in recent years. Data referenced from Britain’s privacy regulator shows a decline:

  • 11 incidents in 2023
  • 4 incidents reported in the following two years

The report notes that more recent data is not available, but the trend described suggests that either detections, reporting, or attack success may have shifted over time.

Even with a decline, incidents like the Department for Education case serve as a reminder that data theft and extortion remain active threats across public services.

What the Department for Education says it did

In its statement, DfE emphasised that it has “robust processes” to protect information and that it took swift action to contain the incident.

The department also reiterated the limited nature of the data involved. The report’s description aligns with DfE’s message: the accessed information was limited to customer service contact details for individuals and organisations, and the department said no other data was reached.

What this means for organisations and individuals

This incident highlights several practical lessons for both organisations and potentially affected individuals:

  • Headlines can be misleading. Large counts may reflect data lines, not unique individuals.
  • Portals matter. Incidents can be confined to specific services, even if the claim is broader.
  • Data extortion still creates risk. Even without system encryption, stolen identifiers like names and email addresses can support follow-on fraud attempts.
  • Policy choices shape outcomes. Government non-payment and tighter rules for public sector payments aim to reduce attacker returns.

While authorities describe the risk to individuals in the DfE case as not high, exposed contact fields can still lead to increased phishing or social engineering attempts—so vigilance remains important.

Conclusion

Ransomware extortion claimed by ExfilSquad has prompted a response from the UK Department for Education after attackers said they accessed more than 600,000 data lines. The department clarified that two portals were impacted and stated that the information involved is limited to customer service contact details, with the risk to individuals not considered high.

In parallel, the Police National Legal Database faced a separate impact involving potentially identifying contact information. With the UK government maintaining a no-ransom stance and pursuing restrictions on payments, the broader goal is clear: reduce the financial leverage that drives extortion schemes across public services.

Source: https://therecord.media/united-kingdom-ransomware-education