Hackers steal data from DfE and police among others



A laptop computer on a desk with code on the screen to visualise the hacker story

Hackers have stolen huge amounts of personal data from the Department for Education (DfE) and the Police National Legal Database (PNLD), exposing sensitive details online.

The attack reportedly targeted 14 other institutions, with a UK university being among them.

Both the DfE and PNLD have reported the breach to the Information Commissioner’s Office (ICO).

The cybercriminal group claiming responsibility calls itself the ExfilSquad. The group, virtually unheard of before the attack, posted sections of the stolen data, including the names and addresses of parents and staff,Β  on a leak website as proof.

According to screenshots seen by the Guardian, they’re demanding payment from both the DfE and PNLD, or have threatened to leak the entire trove. ExfilSquad stated:

The payment we request of you is simply a rounding error compared to the litigation costs of your data leaking. Be smart and just pay.

Hackers’ released details appear ‘legitimate’

The stolen DfE database information relates to the department’s help desk portal, with hackers also having breached the Turing portal, which concerns students studying abroad.

A DfE spokesperson stated:

The information involved is limited to customer service contact details relating to individuals and organisations. No other data has been accessed.

Meanwhile, the PNLD said the details stolen from it related to:

police officers and those working in criminal justice including their name, the force or organisation they work for and their work email address.

The PNLD claimed that no confidential victim, witness or offender information was stolen. However, the hackers gained access to the names and addresses of individuals who submitted questions to the ‘Ask the Police’ service. The portal allows members of the public to get legally verified answers to frequently asked non-emergency policing questions.

TheΒ GuardianΒ reported:

Sophos, a cybersecurity company that provided the screenshots, said the data samples appeared to be legitimate. It added that an account on the social media platform X apparently belonging to the group had been suspended but had been illustrated by a picture of a cybersecurity researcher who had been targeted before by members of the Com, a sprawling ecosystem of native English-speaking hackers.

However, it is understood that the DfE has not seen evidence that ransomware – a type of malicious software that locks up a victim’s IT systems – had been deployed in the hack.

Remember that digital ID scheme?

The news of the significant breach of government databases comes just a week after newly-minted Prime Minister Andy Burnham announced that his administration would scrap his predecessor’s mandatory digital ID scheme entirely.

Starmer had previously announced, back in January, that the scheme would no longer be compulsory for all. However, the right to work in the UK will still be established by fully digital means by 2029.

A spokesperson for Burnham then announced in July that “time and resource that was going to be spent on a national ID scheme will go instead to where it’s most needed, such as helping with the cost of living”.

This reprioritisation of public resource shows a change in direction towards improving everyday life and strengthening local economies over expensive national government schemes.

Critics argued that the database of citizens’ information used to create and manage the digital ID would be vulnerable to hacking and data breaches.

The ExfilSquad leak this week has only served to underscore the truth of that claim: our government cannot (and should not) be trusted to create a secure, centralised database of sensitive public data.

Featured image via Arnold Francisca/ Unsplash

By Grace



Source link

0 0 votes
Article Rating
Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted