A New Hacking Group Hits UK Police and Education Systems: What Happened and Why It Matters

A previously unknown hacking group called ExfilSquad has claimed responsibility for separate breaches of the Police National Legal Database (PNLD) and the Department for Education (DfE) help-desk portal, posting data samples from both on its leak site and demanding payment from each organisation. The PNLD, hosted by West Yorkshire Police, confirmed that 135,000 pieces of data were exposed, while the DfE breach compromised over 600,000 lines of data, according to a report by The Guardian on July 29, 2026, which credited The Times as the first outlet to break the DfE story The Guardian.
The PNLD breach exposed police officer names, force or organisation affiliations, and work email addresses. Also caught in the spill were names and addresses of members of the public who had used the Ask the Police service, a public-facing Q&A resource. The PNLD stated that the database did not hold confidential victim, witness, or offender information, drawing a perimeter around what was and was not exposed. The DfE intrusion, by contrast, targeted the department's help-desk portal and yielded parent and staff contact records: full names, email addresses, phone numbers, and job titles.
ExfilSquad's operational signature fits what cybersecurity professionals call the double-extortion model, which has become standard among ransomware and data-theft groups. In a double-extortion attack, the hackers first steal copies of sensitive data from a target's systems. They then post samples of that data on a public leak site as proof of what they have taken. Finally, they demand a ransom payment, with the threat of releasing the full dataset if the organisation does not pay. Both the DfE and the PNLD were named as targets of the demand. The group had no prior public profile before these claims.
The Guardian's report cites a statement from the PNLD but does not include or reference an official statement from the DfE itself. A police-hosted database acknowledging a breach involving officer identifiers carries immediate operational security concerns, and the PNLD's decision to clarify that no victim, witness, or offender data was held in the compromised system appears designed to limit the damage to administrative and contact-level records rather than investigative material.
The DfE exposure presents a different set of risks. Over 600,000 lines of parent and staff contacts, including phone numbers and job titles, are exactly the kind of data that lends itself to phishing (fraudulent messages designed to trick people into revealing passwords or other sensitive information), social engineering (manipulating people into breaking normal security procedures), and secondary compromise campaigns. Help-desk portals are a well-documented weak point in public-sector infrastructure; they sit at the intersection of high user volume, older authentication systems, and frequently third-party hosting, and they process identity-adjacent data that rarely receives the same access controls as core departmental systems.
The broader context here raises two points worth considering. First, the targeting of both a police-adjacent system and a central government department by the same actor, with simultaneous extortion demands, suggests a coordinated campaign rather than opportunistic exploitation. Whether ExfilSquad is a genuinely new group or a rebrand of an existing operation is an open question that the absence of any prior track record does not resolve. Second, the breach of the PNLD, even limited to administrative data, touches a category of systems that UK policing has historically treated as low-sensitivity because they sit outside case management and evidence chains. The exposure of officer names, force affiliations, and work emails challenges that classification. Correlating an officer's name and force with publicly available duty rosters, social media, or court records can produce an operational profile that adversaries can exploit.
The lack of a DfE statement in the public record, as of The Guardian's July 29 report, leaves open the question of how the department is responding to affected individuals and whether remediation extends beyond the help-desk portal itself. The PNLD's acknowledgement, while limited in scope, at least establishes a public baseline for what was compromised.


