The UK Department for Education confirmed a cyber attack after a previously unknown group, ExfilSquad, claimed it had stolen about 607,000 records from the department’s Help Desk Self-Service Portal and Turing Scheme Portal. The exposed data reportedly included names, email addresses, telephone numbers, and job titles linked to parents, school leaders, university staff, and government officials. The attackers allegedly sought to extort the department by threatening to publish the data rather than encrypt systems, indicating a data-theft-and-extortion operation. The department said it had contained the incident and was working with the National Cyber Security Centre and National Crime Agency on the investigation.
The breach lands amid persistent cyber pressure across UK education, where the government’s 2025/2026 breaches survey found incidents were identified by 49% of primary schools, 73% of secondary schools, 88% of further education colleges, and 98% of higher education institutions. Phishing remained the most common threat, while further and higher education institutions reported broader exposure to impersonation, malware, denial-of-service, and unauthorized access, along with greater operational impact. The survey said education institutions generally maintain stronger governance and technical controls than businesses, but weaknesses in supply-chain security and patch management, combined with budget and staffing constraints and rising concern over AI-enabled social engineering, continue to leave the sector exposed.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
In late July, the UK Department for Education confirmed a cyber attack affecting its Help Desk Self-Service Portal and Turing Scheme Portal. The department said it had taken action to contain the incident and was working with the National Cyber Security Centre and National Crime Agency on the investigation.
The Department for Science, Innovation and Technology and the Home Office published the 2025/2026 Cyber Security Breaches Survey education annex. It reported high breach-identification rates across education institutions, with phishing the dominant threat and further/higher education seeing more frequent and severe impacts.
The quantitative survey and qualitative interviews for the UK Cyber Security Breaches Survey 2025/2026 education annex were conducted between August and December 2025. The research covered state educational institutions including primary and secondary schools, further education colleges, and higher education institutions.
A previously unknown cybercrime group calling itself ExfilSquad claimed responsibility for the Department for Education breach. The group reportedly stole about 607,000 records and attempted to extort the department by threatening to publish the data rather than encrypting systems.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.