mimile
Back to feed
This event is part of a larger story
Франция, Казахстан, Польша: кибератаки раскрыли данные сотен тысяч
Read briefing

UK Department for Education confirms hack of over 600,000 staff records

AI digest

This digest was compiled by AI from multiple sources — links to the originals are below.

UK Department for Education confirms hack of over 600,000 staff records

The UK Department for Education confirmed a data breach that exposed over 600,000 records of head teachers, university staff and government officials. The breach, claimed by the ExfilSquad hacking group, accessed names, job titles and phone numbers via the department's Help Desk Self-Service Portal and Turing Scheme Portal. The DfE stated the risk to individuals is low, even as cybersecurity experts warned the data is a high-value target for spear-phishing campaigns.

Exploited Portals

The breach originated from the DfE’s Help Desk Self-Service Portal and the Turing Scheme Portal, which stored personal details of school and university staff. The ExfilSquad hacking group claimed responsibility for the attack, which compromised over 600,000 records. The DfE confirmed the breach after an internal investigation and is working with the UK’s National Cyber Security Centre (NCSC) and National Crime Agency (NCA). The education sector's reliance on third-party help desk systems and self-service portals has raised concerns about systemic vulnerabilities.

Stolen Data

The accessed records contained names, job titles, and phone numbers of head teachers, university staff, and government officials. While the DfE stated that the breached datasets cannot be connected and the risk to individuals is low, cybersecurity experts warn that such information is a high-value target for spear-phishing campaigns. The data could be used to craft convincing malicious emails, potentially leading to further compromises within educational institutions.

Education Sector Targeting

The UK education industry was the world’s most frequently targeted sector in June, according to cybersecurity reports. This breach follows other public sector incidents, highlighting the vulnerability of government IT systems. The incident has prompted calls for a wider review of sensitive data storage and monitoring across government departments. The DfE is collaborating with the NCSC and NCA to mitigate the breach and prevent future attacks.

What's Next

The NCSC is expected to issue updated guidance for government departments on securing help desk portals by mid-August. It remains unclear whether the ExfilSquad group will publish the stolen data or use it for further targeted attacks.

1 source

UK Department for Education confirms hack of over 600,000 staff records