UK Government Targeted in Extortion Attempts: DfE and Police Database Breached
Cybercriminals are demanding ransom from the UK's Department for Education and have separately compromised a police legal database. The incidents highlight ongoing threats to public sector data, with the government reiterating its policy against making ransom payments.
# UK Government Entities Face Extortion Threats After Data Breaches
Two significant data breaches have impacted UK government entities, leading to extortion demands from cybercriminals. The **Department for Education (DfE)** and the **Police National Legal Database (PNLD)** have both confirmed compromises, prompting investigations and concerns over sensitive information.
## DfE Targeted by ExfilSquad
**ExfilSquad**, an extortion group, claims to have compromised over 600,000 'pieces' of data from the DfE, allegedly including names, email addresses, and phone numbers. The DfE has clarified that this figure refers to lines of data, not individual counts, and asserts that the risk to individuals is not considered high.
The breach specifically impacted the **DfE Help Desk Self-Service Portal** and the **Turing Scheme Portal**. A DfE spokesperson stated, "We have robust processes in place to protect information and took swift action to contain this incident. The information involved is limited to customer service contact details relating to individuals and organisations. No other data has been accessed."
Significantly, **ExfilSquad** has not claimed to have encrypted DfE systems, indicating an exfiltration-focused attack rather than traditional ransomware.
## Police National Legal Database Also Compromised
Separately, the **Police National Legal Database (PNLD)** has been impacted, with approximately 135,000 pieces of data potentially identifying police officers and other criminal justice professionals. This data may include names, forces, and work email addresses.
The **Home Office** has declined to comment on the PNLD breach. However, a spokesperson for the **National Cyber Security Centre (NCSC)** confirmed they are "supporting law enforcement colleagues in response to an incident affecting the Police National Legal Database."
Crucially, the PNLD breach does not involve protected information from ongoing investigations or witness details, mitigating some of the more severe potential consequences.
## Government Policy on Ransom Payments
The British government maintains a strict policy against making ransom payments to cybercriminals. This stance is further reinforced by ongoing legislative efforts. Last year, the government advanced plans to make it illegal for public sector entities and organizations deemed critical national infrastructure to pay ransoms, aiming to curb the ransomware industry.
Data from Britain's privacy regulator indicates a decline in ransomware attacks on central government in recent years, with 11 incidents reported in 2023, followed by only four in the subsequent two years. More recent statistics are currently unavailable.
These incidents serve as a stark reminder of the persistent and evolving threats facing public sector organizations and the critical importance of robust cybersecurity measures and incident response protocols.