ctipilot.ch

UK Department for Education portal and Police National Legal Database breach (July 2026)

incident · incident:uk-dfe-exfilsquad-breach-2026-07

Breach confirmed by the UK Department for Education of two public-facing portals, the DfE Help Desk Self-Service Portal and the Turing Scheme Portal, exposing customer-service contact details of parents, officials, school leaders and university staff, alongside a separately affected Police National Legal Database holding 135,000 records naming officers, their forces and work email addresses. DfE clarified that the claimed figure of more than 600,000 pieces of data refers to lines of data rather than the count of individuals affected, and assessed the risk to individuals as not high; the NCSC is supporting the response, the Home Office declined to comment on the police-database element, and no ransom was paid (The Record, 2026-07-30).

Coverage timeline
1
first 2026-07-31 → last 2026-07-31
Peak priority
notable
1 notable
Sources cited
5
5 hosts
Sections touched
1
active-threats
Co-occurring entities
1
see Related entities below
ATT&CK techniques
2
pinned v19.1 · see below

Hunting pivots

ATT&CK techniques

ATT&CK techniques

2 techniques observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-07-31/exfilsquad-uk-department-for-education-pnld-breach · ATT&CK page ↗

Collection TA0009

T1213Data from Information Repositories×1

Adversaries may leverage information repositories to mine valuable information. Information repositories are tools that allow for storage of information, typically to facilitate collaboration or information sharing between users, and can store a wide variety of data that may aid adversaries in further objectives, such as Credential Access, Lateral Movement, or Defense Evasion, or direct access to the target information. Adversaries may also abuse external sharing features to share sensitive documents with recipients outside of the organization (i.e., Transfer Data to Cloud Account).

Evidence: 2026-07-31/exfilsquad-uk-department-for-education-pnld-breach · ATT&CK page ↗

Story timeline

  1. 2026-07-31UK Department for Education confirms a breach of two public-facing portals and a police legal database, claimed by ExfilSquad — a five-day-old extortion brand whose other 14 claims look fabricated
    active-threatsOne confirmed government breach inside a leak-site victim list that a threat-intel vendor assesses is more likely invented than real

Relationships explore in graph

Typed, source-stated connections from the entity registry — each edge cites the entry whose reporting establishes it.

attributed to

Where this entity is cited

  • active-threats1

Source distribution

  • bleepingcomputer.com1 (20%)
  • cyberinsider.com1 (20%)
  • sec.gov1 (20%)
  • socradar.io1 (20%)
  • therecord.media1 (20%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about UK Department for Education portal and Police National Legal Database breach (July 2026) (1)

2026-07-31 · view entry permalink →

NOTABLENATOB2

UK Department for Education confirms a breach of two public-facing portals and a police legal database, claimed by ExfilSquad — a five-day-old extortion brand whose other 14 claims look fabricated

The UK Department for Education has confirmed a breach of two public-facing portals, the DfE Help Desk Self-Service Portal and the Turing Scheme Portal, with the compromised material described as customer-service contact details — names, email addresses and phone numbers belonging to parents, officials, school leaders and university staff (The Record, 2026-07-30). Separately affected was the Police National Legal Database, where 135,000 records identify police officers by name, force and work email address; The Record notes the database holds no protected information from investigations or witnesses, and that the Home Office, which owns it, declined to comment. The NCSC has confirmed it is supporting law enforcement colleagues on the response. The extortionists are demanding a ransom; The Record notes that as a matter of policy the British government does not make ransom payments, and that the government has moved forward with plans, not yet law, to make such payments illegal for public-sector entities.

Two details in DfE's own response are worth carrying rather than the headline number. It explicitly corrects the criminals' framing, clarifying that the claimed figure of more than 600,000 pieces of data refers to lines of data rather than the count of individuals affected — a victim disputing the arithmetic behind an extortion claim rather than repeating it. And it assesses the risk to individuals as not high, which is consistent with contact-detail exposure rather than anything more sensitive.

The claimant is where this gets interesting. ExfilSquad's Tor leak site first appeared on 2026-07-26 and immediately listed 15 organisations across government, education, finance and technology. SOCRadar's profile of the group is unusually direct about what that list is worth: it assesses that the listings may involve reused data or fabricated allegations, with fabrication currently appearing more likely (SOCRadar, 2026-07-28). No forensic evidence, data samples, victim confirmations or technical detail about initial access are publicly available for the group, and SOCRadar found no aliases, predecessor operations or rebranding history — this is a brand with no track record at all. It also documents the group posting on social media tagging a major vendor's security-intelligence account with a screenshot resembling an internal directory record, authenticity unconfirmed, which reads as publicity-seeking rather than proof.

So the same list contains one independently confirmed national-government breach and fourteen claims a credible vendor thinks are probably invented. One of the listed companies, semiconductor manufacturer Analog Devices, was added and then quietly removed — the outlet that reported the removal says the reason is unknown and notes that delisting is common when ransom negotiations begin (BleepingComputer, 2026-07-30). Analog Devices separately filed a regulatory disclosure stating it identified unauthorized access to certain systems on 23 June 2026, that its investigation found certain files were exfiltrated, and that it does not believe the incident is reasonably likely to materially impact its business — filed under the non-material "Other Events" item despite the acknowledged exfiltration, which is itself a useful materiality-threshold data point for anyone calibrating their own disclosure playbook (Analog Devices, 2026-07-29). The company has not attributed that intrusion to ExfilSquad or confirmed the group's claims are related, and the record count circulating alongside it is the group's own allegation rather than a company figure (CyberInsider, 2026-07-30). Those are two threads, and the available reporting does not join them.

135,000 pieces of data potentially identifying the names, forces and work email addresses of police officers

The Record (Recorded Future News) 2026-07-30

the listings may involve reused data or fabricated allegations, with fabrication currently appearing more likely

SOCRadar 2026-07-28
incident31 Jul 04:09Zmulti-sourceOpen finding ↗