Data breach at Department for Education exposes thousands of records
The names and phone numbers of thousands of school leaders, university staff, and government officials have been leaked onto the dark web after the Department for Education (DfE) was hacked, reports BritPanorama.
Online thieves reportedly stole 607,000 records in the attack, including full names, job titles, and email addresses of individuals who have engaged with the department.
According to The Times, which first reported the breach, the hackers targeted the DfE help desk, managing requests from local authorities and school leaders, and records from the Turing Scheme – the database used by education institutions to oversee UK students studying overseas.
DfE sources informed The Independent that the data protection risk to those affected is not considered high, highlighting that the obtained data consists of disparate sets which cannot be easily connected.
They are understood to have reported the incident to the Information Commissioner’s Office and are collaborating with the National Crime Agency (NCA) and National Cyber Security Centre (NCSC).
The department is reportedly working to fix the help desk portal and the Turing Scheme portal following the hack and has switched telephone communication during the maintenance period.
Dark web posts seen by The Times indicate that a cybercriminal group known as ExfilSquad has claimed responsibility for the breach.
Jake Moore, an adviser at European cybersecurity firm ESET, cautioned that government agencies pose as “soft targets” for cybercriminals, asserting that this attack “isn’t a one off.”
He noted: “Government agencies often lack proper funding and consequently may not have the best protection for their systems, making them soft targets for cybercriminals. With weaker security, government agencies can also become unintentionally entangled in ransomware attacks aimed at other companies.”
Moore emphasized the need for the UK government to learn from its mistakes, as similar incidents have adversely affected local government agencies in the past, leading to prolonged disruptions with broader implications for communities.
He added, “When information like this is stolen, criminals can do a lot by piecing together a data jigsaw and creating convincing follow-up phishing emails to lure individuals into malicious sites. It’s best to remain vigilant against any unsolicited communication.”
A Department for Education spokesperson stated: “We have robust processes in place to protect information and took swift action to contain this incident. The information involved is limited to customer service contact details relating to individuals and organisations. No other data has been accessed.”
“We continue to work closely with the National Cyber Security Centre and the National Crime Agency.”