UK Government Cyber Attack Exposes 740,000 Records in Major Education and Police Data Breach

When news broke in July 2026 that the hacking group ExfilSquad had claimed a major scalp, the initial shock figure was impossible to ignore: over 740,000 records stolen from UK government systems. But as the picture sharpened, a more nuanced — and in some ways more alarming — story emerged. What looked like a single catastrophic leak from the Department for Education was actually two separate breaches orchestrated by the same group. Around 607,000 of those records came directly from DfE portals, while roughly 135,000 more were pulled from the Police National Legal Database, a system used by UK forces for legal guidance.

UK Department for Education cyberattack showing a government building, breached server, and exposed personal data documents

I’ve watched enough incidents to recognise this pattern instantly. Attackers rarely stop at one door when they find a corridor of unlocked rooms. The ExfilSquad campaign isn’t just a number to gawk at; it’s a textbook case of how fragmented data governance, over-retained directories, and porous access controls can combine into a single, very expensive morning for the people responsible.

What Actually Happened in the July 2026 Attack

In late July 2026, ExfilSquad — a threat actor known for targeting government bodies — announced it had successfully infiltrated two separate data stores. The first, and by far the largest, was the Department for Education’s help desk system and the Turing Scheme portal. These platforms held detailed contact records for staff, scheme participants, and partners: names, email addresses, job titles, and internal contact details. The attackers claimed to have walked away with approximately 607,000 entries.

The second target was the Police National Legal Database. This resource contains legal guidance, case law updates, and procedural information used by officers across England and Wales. From this system, ExfilSquad extracted around 135,000 records — again, predominantly names and contact information rather than sensitive operational material. The combined haul exceeded 740,000 records, a number the group was quick to publicise.

No financial data, passwords, or national insurance numbers have been confirmed in the exposed datasets. That doesn’t make the breach trivial. The information is a goldmine for targeted phishing campaigns, social engineering, and impersonation attacks. A scammer who knows your name, workplace, and role can craft a message that looks entirely convincing. And when a police-linked database is involved, the potential for credential harvesting across law enforcement agencies becomes a serious concern.

Why This Breach Is a Textbook Example of What Not to Do

Every data breach has its own technical signature, but the root causes tend to fall into a depressingly small set of buckets. This incident fills four of them perfectly.

Data Breach 101: Too Much Information in One Place

The DfE breach alone delivered over 600,000 records. That figure tells you immediately that directory-style information was aggregated and accessible from a single point — likely a help desk or portal backend that wasn’t designed to limit bulk retrieval. Best practice says you segment large datasets, apply rate limiting, and regularly purge outdated contacts. When one compromise gives an attacker the equivalent of a departmental phonebook, data minimisation clearly hasn’t been taken seriously.

The Insider and Social Engineering Risk

ExfilSquad hasn’t published its initial access method, but breaches of this scale rarely begin with a sophisticated zero-day exploit. The far more common route is a well-crafted phishing email, a reused password harvested from an earlier leak, or a third-party account that was never properly offboarded. In an environment where staff juggle dozens of logins and multi-factor authentication prompts, the human layer remains the softest target. One distracted click can unlock an entire directory.

Third-Party Exposure: The Weak Link Nobody Talks About

The fact that one group hit both the DfE and a police legal database within the same campaign strongly suggests a shared supply chain vulnerability. It could be a common IT contractor, a federated identity provider, or simply credentials that worked across multiple government systems. Organisations constantly outsource platform management, and each external partner inherits the same access privileges as internal staff — but often without the same security controls. You can lock your own doors perfectly, but if your contractor leaves a window open, the damage is the same.

Data Protection Failure at a Human Level

A breach isn’t just a technology problem; it’s a failure of process and culture. Someone inside each organisation decided how long to keep those contact records, who could access them, and how they should be protected. Exposing a staff directory might sound like low-grade metadata, but under the UK GDPR and Data Protection Act 2018, it’s personal data that demands proportionate security. When over 740,000 records leak across two systems, the question isn’t just “how did the attacker get in?” but “why was all of this still sitting there, unredacted and reachable?”

The Real-World Impact of Losing Contact Records at This Scale

“It’s only names and emails” is a dangerous sentence. Here’s what a malicious actor can actually do with this dataset.

Every person in that 740,000-record pool is now a high-priority spear-phishing target. A message that opens with “Dear [First Name], regarding your role as [Job Title] at the Department for Education…” will bypass mental spam filters far more easily than a generic greeting. If the attacker also managed to grab email signature blocks or internal formatting, they can produce near-perfect clones of legitimate messages. Once a single recipient clicks through and enters a password, the attacker pivots from data theft to full account takeover.

Criminals also specialise in chaining breaches together. Marry these newly exposed identities with older data dumps containing home addresses or dates of birth, and suddenly you have enough to commit identity fraud, apply for credit, or hijack online accounts. The police database records add an extra layer of concern: an attacker who impersonates a law enforcement official can open doors that ordinary phishing attempts never could.

Then there’s the institutional cost. The Department for Education and the police forces involved will now spend months managing regulatory fallout, fielding complaints, and rebuilding trust — all because basic contact information was left in a system that wasn’t hardened enough to keep it safe.

What Organisations Should Learn and Do Right Now

If you’re responsible for any dataset that contains personal information, even “just” a directory of names and roles, this breach is your immediate wake-up call.

  • Audit third-party access without mercy. Map every supplier, contractor, and shared platform that touches your systems. Apply the principle of least privilege: grant only the access that is strictly necessary, revoke it automatically when contracts end, and review those permissions more often than once a year. The connection between DfE portals and the Police National Legal Database suggests that overlooked third-party access was either the entry point or the bridge.
  • Lock down authentication across the board. Multi-factor authentication must be non-negotiable for every user, internal and external. Crucially, train people to recognise MFA fatigue attacks — those relentless notification floods that try to trick someone into tapping “Approve” just to make the noise stop. One successfully hijacked session is all it takes.
  • Embrace aggressive data minimisation. Go through your directories and ask a blunt question: do we genuinely need to store this person’s email address, job title, and internal location in a searchable portal that could be scraped? If the answer is no, strip it out or restrict access to a tightly controlled view. Every field you remove is one less thing to leak.
  • Run phishing simulations that mimic real threats. Generic “click here to win a voucher” tests don’t prepare people for messages that look like internal IT tickets or government updates. Tailor your simulations to the type of content your teams actually see, and treat every failed exercise as a coaching opportunity rather than a gotcha moment.
  • Test your incident response plan on a random Tuesday. Plans that sit on a shelf gathering dust don’t work when an incident kicks off at 4:45 p.m. on a Friday. Run a live drill that involves isolating a system, notifying stakeholders, and making hard decisions about public disclosure under time pressure. The first 60 minutes of a real breach will reveal every gap you didn’t know you had.

What Individuals Can Do to Protect Themselves

If you think your data might have been caught up in either the DfE portal breach or the police database leak, take a few practical steps right now.

  • Treat your inbox with heightened suspicion. Expect an increase in targeted messages that reference your role, employer, or a plausible internal request. Don’t click links in unsolicited emails, and never supply login credentials because an email asked you to.
  • Stop password reuse immediately. If your work email address has ever been paired with the same password on a shopping site, a social network, or a legacy forum account, change that password now. A password manager makes this habit sustainable.
  • Switch on multi-factor authentication everywhere. This applies to personal email, banking, social media, and anything else that matters. It is the single most effective barrier against credential-based attacks.
  • Don’t ignore official breach notifications. If the Department for Education or your employer contacts you directly, follow their advice — which may include enrolling in credit monitoring or identity protection services. That support exists for a reason.

A Predictable Pattern We Can Still Break

The ExfilSquad campaign doesn’t read like a spy novel. It reads like a case study of what happens when large institutions accumulate too much personal data, grant wide access to third parties, and assume that directories aren’t sensitive enough to protect aggressively. The 607,000 DfE records and the 135,000 police database entries together form a dataset that will now be traded, cross-referenced, and weaponised for years.

But here’s the part that keeps me cautiously optimistic: none of this required breakthrough technology to prevent. It required the boring, disciplined work of least-privilege access, real data minimisation, and consistent human training. Organisations that finally treat those fundamentals as urgent will stop being the next headline. Everyone else will keep wondering why the same thing keeps happening to different names.