
Encryption in the spotlight: Cure or Curse?
Has encryption given us a false sense of security by luring us into assuming that if our data is safe a lot of the time, we can act as though it is safe all of the time?


If you visit the Department for Education (DfE) page on the UK government’s GOV.UK portal today, you’ll find a long list of links to articles published over the past few days.
To be fair, these articles cover a wide range of topics, and suggest a welcome level of openness, from grants for free school meals, through teacher training statistics, to statutory disclosures of roles and salaries in the DfE itself.
What you won’t find at the time of writing [2026-07-30T21:08:00Z], however, is a link to help you fathom a recently publicized breach at the DfE, which media reports suggest involve more 600,000 data records stolen by a cyberextortion gang going by ExfilSquad.
Exfil, of course, is short for exfiltration, the espionage world’s jargon term adopted by the cybersecurity industry to describe what most of us just refer to as “stolen data.”
This fancy word sometimes makes data breaches sound more complex and sophisticated than they really were, and thus that the victims were somehow carefully targeted or unfortunate to get breached in the first place.
But the recent sentencing of youthful UK cybercriminals Thalha Jubair and Owen Flowers reminds us that many if not most contemporary breaches are neither the work of so-called state-sponsored attackers nor the outcome of well-funded international political hacktivism.
Jubair and Flowers are only 20 and 19 now, so they were younger still in 2024 when they breached Transport for London, stole data, and disrupted operations; despite their youth, both were identified in court hearings to have multi-million dollar stashes of cryptocurrency under their control at the time.
Jubair already had 22 previous convictions, including for fraud, unauthorized computer access, blackmail, and stalking. Flowers had refused to take part in a youth rehabilitation program aimed at deflecting him from cybercriminality. It’s easy to see why youngsters might be willing to risk lengthy prison sentences if they already have millions in “anonymous money” up their sleeves.
Reports say that ExfilSquad have demanded money from not only from the DfE, but also from the Police National Legal Database (PNLD), which was apparently also breached, and other organizations, presumably in return for “deleting” the stolen data rather than selling it on or dumping it publicly to provoke lawsuits against the affected bodies:
The payment we request of you is simply a rounding error compared to the litigation costs of your data leaking. Be smart and just pay.
Threatening behavior indeed.
So, far, the DfE seems to have said very little about this incident, which is understandable given that investigation into the attack has only just started.
But the BBC reports that a DfE spokesperson played it down with a comment that many readers may consider a little less humble or apologetic than might have been expected:
We have robust processes in place to protect information and took swift action to contain this incident. The information involved is limited to customer service contact details relating to individuals and organizations. No other data has been accessed.
Also, DfE was quick to note that the figure of 670,000 “breached items” refers to the number of database records stolen, not the number of individuals affected, presumably reflecting that some individuals had more than one entry in the list.
(Telephone numbers and email addresses are said to be among the data items snapped up by the crooks, so it’s reasonable to assume that some users will have multiple records against their names.)
What’s not clear is exactly what the words “individuals” and “organizations” refer to – we don’t yet know whether these include schools, teachers and students, or just contractors and those who provide services directly to the department.
Why not ask how SolCyber can help you do cybersecurity in the most human-friendly way? Don’t get stuck behind an ever-expanding convoy of security tools that leave you at the whim of policies and procedures that are dictated by the tools, even though they don’t suit your IT team, your colleagues, or your customers!
Paul Ducklin is a respected expert with more than 30 years of experience as a programmer, reverser, researcher and educator in the cybersecurity industry. Duck, as he is known, is also a globally respected writer, presenter and podcaster with an unmatched knack for explaining even the most complex technical issues in plain English. Read, learn, enjoy!

Has encryption given us a false sense of security by luring us into assuming that if our data is safe a lot of the time, we can act as though it is safe all of the time?

Guest author, Chris Witham, Director of Operations, Sicarius For over 20 years, Chris has honed his skills across a wide variety of IT disciplines, including systems administration, IT security, digital forensics, risk and compliance, and incident response. Chris has provided first-rate digital forensic services for cutting edge organisations in federal law enforcement and private enterprise, both locally in Australia and Internationally. His resume includes working with the Australian Federal Police, Blackpanda and KordaMentha, supporting sophisticated, and at times high-profile investigations. […]

New HIPAA regulations now demand adherence. Find out what’s required.

By subscribing you agree to our Privacy Policy and provide consent to receive updates from our company.






