Home
Blog
Blackmailers going by “ExfilSquad” claim breaches against UK orgs supporting education and police

Blackmailers going by “ExfilSquad” claim breaches against UK orgs supporting education and police

Paul Ducklin
07/30/2026
Share this article:

Who attacked whom?

If you visit the Department for Education (DfE) page on the UK government’s GOV.UK portal today, you’ll find a long list of links to articles published over the past few days.

To be fair, these articles cover a wide range of topics, and suggest a welcome level of openness, from grants for free school meals, through teacher training statistics, to statutory disclosures of roles and salaries in the DfE itself.

What you won’t find at the time of writing [2026-07-30T21:08:00Z], however, is a link to help you fathom a recently publicized breach at the DfE, which media reports suggest involve more 600,000 data records stolen by a cyberextortion gang going by ExfilSquad.

Exfil, of course, is short for exfiltration, the espionage world’s jargon term adopted by the cybersecurity industry to describe what most of us just refer to as “stolen data.”

This fancy word sometimes makes data breaches sound more complex and sophisticated than they really were, and thus that the victims were somehow carefully targeted or unfortunate to get breached in the first place.

But the recent sentencing of youthful UK cybercriminals Thalha Jubair and Owen Flowers reminds us that many if not most contemporary breaches are neither the work of so-called state-sponsored attackers nor the outcome of well-funded international political hacktivism.

Jubair and Flowers are only 20 and 19 now, so they were younger still in 2024 when they breached Transport for London, stole data, and disrupted operations; despite their youth, both were identified in court hearings to have multi-million dollar stashes of cryptocurrency under their control at the time.

Blackmailers going by "ExfilSquad" claim breaches against UK orgs supporting education and police - SolCyber

Jubair already had 22 previous convictions, including for fraud, unauthorized computer access, blackmail, and stalking. Flowers had refused to take part in a youth rehabilitation program aimed at deflecting him from cybercriminality. It’s easy to see why youngsters might be willing to risk lengthy prison sentences if they already have millions in “anonymous money” up their sleeves.

Who did it?

Reports say that ExfilSquad have demanded money from not only from the DfE, but also from the Police National Legal Database (PNLD), which was apparently also breached, and other organizations, presumably in return for “deleting” the stolen data rather than selling it on or dumping it publicly to provoke lawsuits against the affected bodies:

The payment we request of you is simply a rounding error compared to the litigation costs of your data leaking. Be smart and just pay.

Threatening behavior indeed.

What was said?

So, far, the DfE seems to have said very little about this incident, which is understandable given that investigation into the attack has only just started.

But the BBC reports that a DfE spokesperson played it down with a comment that many readers may consider a little less humble or apologetic than might have been expected:

We have robust processes in place to protect information and took swift action to contain this incident. The information involved is limited to customer service contact details relating to individuals and organizations. No other data has been accessed.

Also, DfE was quick to note that the figure of 670,000 “breached items” refers to the number of database records stolen, not the number of individuals affected, presumably reflecting that some individuals had more than one entry in the list.

(Telephone numbers and email addresses are said to be among the data items snapped up by the crooks, so it’s reasonable to assume that some users will have multiple records against their names.)

What’s not clear is exactly what the words “individuals” and “organizations” refer to – we don’t yet know whether these include schools, teachers and students, or just contractors and those who provide services directly to the department.

What to do?

  • If you work for DfE (directly, indirectly, or under contract), note that the Department may contact you if you were personally affected. Watch for further notices from DfE, but if you are invited to make contact with an individual or a company for “help” with this breach, don’t use contact data provided in an email, phone call, or other message. Scammers regularly try to use breach stories to open the door to further criminality. Find your own way to contact the DfE via documentation you already have, such as contracts, invoices, receipts, or printed paperwork from before the breach happened.
  • If you hold other people’s data, remember that you may yourself end up in the uncomfortable position of needing to publish a breach notification in the future. Preparing for failure is not an admission that you intend to fail, and is much better than failing to prepare.
  • If you ever need to write a breach response, consider avoiding phrases such as “we take your security seriously,” or “we have robust processes in place,” given that any breach suggests that you didn’t, in fact, take security seriously enough, and didn’t have sufficiently robust processes in place to prevent an attack. Plain-speaking information about what you are currently doing, how long you expect it to take before you have something conclusive to say, and how you will communicate in future, are all useful details to provide if you don’t yet have answers or solutions.

Why not ask how SolCyber can help you do cybersecurity in the most human-friendly way? Don’t get stuck behind an ever-expanding convoy of security tools that leave you at the whim of policies and procedures that are dictated by the tools, even though they don’t suit your IT team, your colleagues, or your customers!

Blackmailers going by "ExfilSquad" claim breaches against UK orgs supporting education and police - SolCyber


More About Duck

Paul Ducklin is a respected expert with more than 30 years of experience as a programmer, reverser, researcher and educator in the cybersecurity industry. Duck, as he is known, is also a globally respected writer, presenter and podcaster with an unmatched knack for explaining even the most complex technical issues in plain English. Read, learn, enjoy!

Paul Ducklin
Paul Ducklin
07/30/2026
Share this article:

Table of contents:

The world doesn’t need another traditional MSSP 
or MDR or XDR.

What it requires is practicality and reason.

Related articles

Choose identity-first managed security.

We start with identity and end with transparency — protecting where attacks begin and keeping you informed, with as much visibility as you want. No black boxes, just clear, expert-driven security.
No more paying for useless bells and whistles.
No more time wasted on endless security alerts.
No more juggling multiple technologies and contracts.

Follow us!

Subscribe

Join our newsletter to stay up to date on features and releases.

By subscribing you agree to our Privacy Policy and provide consent to receive updates from our company.

©
2026
SolCyber. All rights reserved
|
Made with
by
Jason Pittock

I am interested in
SolCyber DPM++

I am interested in
SolCyber XDR++™

I am interested in
SolCyber MDR++™

I am interested in
SolCyber Extended Coverage™

I am interested in
SolCyber Foundational Coverage™

I am interested in a
Free Demo

14624