Foresight IT Services cyber security graphic

The UK Department for Education has been listed on the leak site of a ransomware group calling itself ExfilSquad, which claims to have stolen around 607,000 contact records — names, emails, phone numbers and job titles belonging to parents and staff — from two of its portals. It’s worth stressing that this is currently the attackers’ own claim and hasn’t been independently confirmed, but the pattern is all too familiar.

Groups like this typically get in through a phishing email or an exposed remote-access service, quietly copy data out, then deploy ransomware and threaten to publish what they’ve taken unless they’re paid. If a government department with serious resources can be caught out, the lesson for every business and school is simple: no one is too obscure to be a target.

Two things do the heavy lifting here. First, multi-factor authentication (MFA) on every account — it’s the single most effective control against the stolen and phished credentials these attacks rely on. Second, continuous monitoring — the difference between catching an intrusion in hours and reading about it on a leak site months later. If you’re not certain both are in place across your organisation, that’s the conversation to have this week.

Source: GalaxyWarden Threat Research, 26 July 2026.