Dan Milmo and Vikram Dodd 

Hackers steal sensitive data from UK Department for Education and police

Details of parents and staff, including email addresses and phone numbers, are among data taken by cybercriminals
  
  

A screen with the word
The police national legal database hack includes the theft of passwords used to access the site. Photograph: Dave Hunt/AAP

The Department for Education and a police database have been targeted by a cyber-attack, exposing more than 740,000 pieces of data.

Details of government officials, senior school leaders, university staff, police officers and members of the public have been taken by hackers.

Just over 600,000 lines of data have been stolen from the DfE’s help-desk portal. They show parent and staff contacts including full names, email addresses, phone numbers and job titles, according to a “leak” website set up by the hackers.

A smaller package of similar data has been taken from the department’s Turing portal, which manages a scheme for students studying abroad.

The hackers have also breached the police national legal database (PNLD), which provides legal assistance to UK police forces. The cybercriminals claimed to have taken 135,000 pieces of data.

The PNLD said the details taken related to “police officers and those working in criminal justice including their name, the force or organisation they work for and their work email address”.

Some names and addresses of members of the public who had previously submitted a question to the Ask the Police service had also been taken. It said the database did not hold confidential victim, witness or offender information.

While embarrassing, the breach of the police legal database is not thought to be serious.

A previously unknown hacking gang calling itself ExfilSquad claimed it had carried out the attack and posted samples of the data on its leak site, a typical gambit for cybercriminals seeking money for the information they have stolen.

The hackers are demanding a payment from the DfE and PNLD in exchange for not posting all the data, according to screen grabs seen by the Guardian.

The message states that only a small sample of data has been posted for now but indicates that all of it will be uploaded if the DfE, PNLD and other hacking victims do not make an unspecified payment.

“The payment we request of you is simply a rounding error compared to the litigation costs of your data leaking. Be smart and just pay,” said the gang.

The message is apparently directed at 14 hacking victims including the DfE. The list of alleged victims includes a UK university that has been contacted by the Guardian.

Sophos, a cybersecurity company that provided the screenshots, said the data samples appeared to be legitimate. It added that an account on the social media platform X apparently belonging to the group had been suspended but had been illustrated by a picture of a cybersecurity researcher who had been targeted before by members of the Com, a sprawling ecosystem of native English-speaking hackers.

However, it is understood that the DfE has not seen evidence that ransomware – a type of malicious software that locks up a victim’s IT systems – had been deployed in the hack.

The Times, which first reported the DfE hack, said the data included details of government officials, senior school leaders and university staff. The DfE is responsible for early years, schools, higher and further education in England.

The PNLD hack includes the theft of passwords used to access the site.

One senior source briefed on the PNLD leak said: “The risk is low. The question is, if you use your password for the PNLD, do you use it for more sensitive systems?”

The database is hosted by West Yorkshire police and is open for forces across England and Wales to view.

The source added that it was “early days in our understanding of what has happened.”

Any hack of two other police databases – the police national database and the police national computer – would have been deemed far more serious. It is not believed that any direct information about officers in sensitive postings could be gleaned from the data leaked.

The government said it was working closely with the National Cyber Security Centre and the National Crime Agency on the DfE hack. The DfE and PNLD have also reported the incident to the Information Commissioner’s Office, the data watchdog.

The DfE said “swift action” had been taken to contain the incident.

“The information involved is limited to customer service contact details relating to individuals and organisations,” it said. “No other data has been accessed.”

It is understood the help-desk data includes different sets of data that cannot be connected to each other easily.

 

Leave a Comment

Required fields are marked *

*

*