World

Hackers Hit UK Police and Education Records: A Plain-English Guide

Elena MarquezPublished 2d ago4 min readBased on 1 source
Reading level
Hackers Hit UK Police and Education Records: A Plain-English Guide

A hacking group called ExfilSquad, which no one had heard of before, says it broke into two separate UK government systems: the Police National Legal Database (PNLD) and the Department for Education (DfE) help-desk portal. The group posted samples of stolen data online and demanded payment from both organisations. The PNLD, which is run by West Yorkshire Police, confirmed that 135,000 pieces of data were exposed. The DfE breach involved over 600,000 lines of data. These details were reported by The Guardian on July 29, 2026, which credited The Times as the first to report the DfE story The Guardian.

The PNLD breach exposed police officer names, which police force they belong to, and their work email addresses. Names and addresses of ordinary people who had used a service called Ask the Police, a public Q&A website, were also caught up in the spill. The PNLD said the database did not hold confidential information about victims, witnesses, or offenders, which helps clarify what was and was not exposed. The DfE break-in targeted the department's help-desk portal and resulted in the theft of parent and staff contact details: full names, email addresses, phone numbers, and job titles.

The method ExfilSquad used follows a pattern that has become common among hacking groups. It works in three steps. First, the hackers secretly copy sensitive data from a target's computer systems. Second, they post a small sample of that data on a public website to prove they really have it. Third, they demand a ransom payment, threatening to release all the stolen data if the organisation does not pay. Both the DfE and the PNLD were named as payment targets. ExfilSquad had no public history before making these claims.

The Guardian's report includes a statement from the PNLD but does not reference any official statement from the DfE. When a police-run database admits that officer names and emails were stolen, that creates immediate security concerns. The PNLD's decision to clarify that no victim, witness, or offender data was stored in the compromised system appears aimed at limiting the damage to administrative records rather than investigative files.

The DfE exposure carries different risks. Over 600,000 lines of parent and staff contact details, including phone numbers and job titles, are exactly the kind of information scammers can use to send convincing fake emails or make phone calls designed to trick people into giving up passwords or other sensitive details. Help-desk portals are a known weak spot in government technology. They handle large numbers of users, often run on older security systems, and are sometimes managed by outside companies. They also deal with personal information that does not always get the same level of protection as a department's core systems.

The broader picture here raises two concerns worth thinking about. First, the fact that the same group targeted both a police-connected system and a central government department, with ransom demands at the same time, suggests this was a planned campaign rather than a random attack. Whether ExfilSquad is truly new or just an existing group operating under a new name is a question that their lack of history does not answer. Second, the PNLD breach, even though it only involved administrative data, affects a type of system that UK policing has long considered low-risk because it sits outside the databases used for investigations and evidence. But exposing officer names, forces, and work emails challenges that view. Someone who knows an officer's name and force can look up public duty schedules, social media accounts, or court records to build a detailed picture of that officer's work.

As of The Guardian's July 29 report, the DfE has not made a public statement about the breach. That leaves questions open about how the department is responding to the people affected and whether the fix goes beyond just the help-desk portal. The PNLD's acknowledgement, while limited, at least gives the public a starting point for understanding what was taken.