A previously unknown cybercrime group calling itself ExfilSquad has emerged by claiming attacks against 15 organisations across the public and private sectors, including the UK’s Department for Education (DfE), the Police National Legal Database (PNLD) and several well-known international companies. So far, only the incidents involving the DfE and the PNLD have been acknowledged by the affected organisations, while the group’s remaining claims have not been independently verified.
The DfE confirmed that it recently responded to a cybersecurity incident and said it acted quickly to contain the breach. According to the department, the exposed information is limited to customer service contact details associated with individuals and organisations, adding that there is currently no evidence that other categories of information were accessed. The department has notified the Information Commissioner’s Office and is working with the National Cyber Security Centre and the National Crime Agency as the investigation continues.
ExfilSquad’s version of events differs significantly. The group claims it copied roughly 600,000 Help Portal records together with approximately 7,000 records linked to the UK’s Turing Scheme, which supports international education exchanges. The attackers allege the data includes names, email addresses, telephone numbers and job titles belonging to parents and education staff. Those claims have not been confirmed by the DfE.
Although the department maintains that the compromised information was limited, cybersecurity specialists warn that contact information alone can be valuable to attackers. Frank van Oeveren, Associate Director for Global Threat Intelligence at NCC Group, said such information can be used to build convincing phishing campaigns, business email compromise attacks and other forms of social engineering. He also noted that educational organisations remain frequent targets because they manage large amounts of personal data while often operating complex technology environments.
The group has also claimed responsibility for breaching the Police National Legal Database, a legal reference system used by police forces in England and Wales. According to ExfilSquad, it obtained approximately 1.9 GB of data containing around 135,000 records, including names, work email addresses and police force affiliations. The PNLD has confirmed that data was taken from its systems but said the incident did not expose confidential information relating to victims, witnesses or offenders. Officials also acknowledged that credentials used to access the platform were among the compromised data, while stating they believe the risk to more sensitive systems remains low.
Beyond the two confirmed incidents, ExfilSquad has listed a number of additional organisations on its leak site, including Microsoft, Frontier Airlines, Allstate, the City of Houston and the City of Atlanta. The group alleges it stole large volumes of internal information from several of those organisations, but none of the companies have confirmed the claimed breaches. Security researchers have also suggested that some of the data promoted by ExfilSquad may originate from previously reported incidents rather than newly compromised systems.
With multiple investigations still underway, it remains unclear whether ExfilSquad is responsible for all of the attacks it claims or whether some of the published datasets have been repackaged from earlier breaches. For now, the confirmed incidents involving the UK’s education and policing sectors are the only attacks publicly acknowledged by the affected organisations.
