
Craneware Group reports huge healthcare data breach, plays down risks
Company says that some of the stolen data was public already… but not all of it!


If you visit the Department for Education (DfE) page on the UK government’s GOV.UK portal today, you’ll find a long list of links to articles published over the past few days.
To be fair, these articles cover a wide range of topics, and suggest a welcome level of openness, from grants for free school meals, through teacher training statistics, to statutory disclosures of roles and salaries in the DfE itself.
What you won’t find at the time of writing [2026-07-30T21:08:00Z], however, is a link to help you fathom a recently publicized breach at the DfE, which media reports suggest involve more 600,000 data records stolen by a cyberextortion gang going by ExfilSquad.
Exfil, of course, is short for exfiltration, the espionage world’s jargon term adopted by the cybersecurity industry to describe what most of us just refer to as “stolen data.”
This fancy word sometimes makes data breaches sound more complex and sophisticated than they really were, and thus that the victims were somehow carefully targeted or unfortunate to get breached in the first place.
But the recent sentencing of youthful UK cybercriminals Thalha Jubair and Owen Flowers reminds us that many if not most contemporary breaches are neither the work of so-called state-sponsored attackers nor the outcome of well-funded international political hacktivism.
Jubair and Flowers are only 20 and 19 now, so they were younger still in 2024 when they breached Transport for London, stole data, and disrupted operations; despite their youth, both were identified in court hearings to have multi-million dollar stashes of cryptocurrency under their control at the time.
Jubair already had 22 previous convictions, including for fraud, unauthorized computer access, blackmail, and stalking. Flowers had refused to take part in a youth rehabilitation program aimed at deflecting him from cybercriminality. It’s easy to see why youngsters might be willing to risk lengthy prison sentences if they already have millions in “anonymous money” up their sleeves.
Reports say that ExfilSquad have demanded money from not only from the DfE, but also from the Police National Legal Database (PNLD), which was apparently also breached, and other organizations, presumably in return for “deleting” the stolen data rather than selling it on or dumping it publicly to provoke lawsuits against the affected bodies:
The payment we request of you is simply a rounding error compared to the litigation costs of your data leaking. Be smart and just pay.
Threatening behavior indeed.
So, far, the DfE seems to have said very little about this incident, which is understandable given that investigation into the attack has only just started.
But the BBC reports that a DfE spokesperson played it down with a comment that many readers may consider a little less humble or apologetic than might have been expected:
We have robust processes in place to protect information and took swift action to contain this incident. The information involved is limited to customer service contact details relating to individuals and organizations. No other data has been accessed.
Also, DfE was quick to note that the figure of 670,000 “breached items” refers to the number of database records stolen, not the number of individuals affected, presumably reflecting that some individuals had more than one entry in the list.
(Telephone numbers and email addresses are said to be among the data items snapped up by the crooks, so it’s reasonable to assume that some users will have multiple records against their names.)
What’s not clear is exactly what the words “individuals” and “organizations” refer to – we don’t yet know whether these include schools, teachers and students, or just contractors and those who provide services directly to the department.
Why not ask how SolCyber can help you do cybersecurity in the most human-friendly way? Don’t get stuck behind an ever-expanding convoy of security tools that leave you at the whim of policies and procedures that are dictated by the tools, even though they don’t suit your IT team, your colleagues, or your customers!
Paul Ducklin is a respected expert with more than 30 years of experience as a programmer, reverser, researcher and educator in the cybersecurity industry. Duck, as he is known, is also a globally respected writer, presenter and podcaster with an unmatched knack for explaining even the most complex technical issues in plain English. Read, learn, enjoy!

Company says that some of the stolen data was public already… but not all of it!

If HTTPS provides true end-to-end encryption, how do web firewalls crack into your network traffic? And what stops cybercriminals doing the same thing?

Are the shiniest new threats worse than the disruptive disorder of history?

By subscribing you agree to our Privacy Policy and provide consent to receive updates from our company.






