The UK Department for Education has been listed on the leak site of a ransomware group calling itself ExfilSquad, which claims to have stolen around 607,000 contact records — names, emails, phone numbers and job titles belonging to parents and staff — from two of its portals. It’s worth stressing that this is currently the attackers’ own claim and hasn’t been independently confirmed, but the pattern is all too familiar.
Groups like this typically get in through a phishing email or an exposed remote-access service, quietly copy data out, then deploy ransomware and threaten to publish what they’ve taken unless they’re paid. If a government department with serious resources can be caught out, the lesson for every business and school is simple: no one is too obscure to be a target.
Two things do the heavy lifting here. First, multi-factor authentication (MFA) on every account — it’s the single most effective control against the stolen and phished credentials these attacks rely on. Second, continuous monitoring — the difference between catching an intrusion in hours and reading about it on a leak site months later. If you’re not certain both are in place across your organisation, that’s the conversation to have this week.
What it means for schools and SMEs
Education and its suppliers are attractive targets: they hold large volumes of personal data on children, parents and staff, and often run stretched IT with many users and legacy systems. But the routes in — a phishing email, an exposed remote-access service, a stolen password — are exactly the same ones used against businesses of every kind. The reassuring flip side is that the same two controls do most of the work everywhere: multi-factor authentication on every account, and continuous monitoring to catch an intrusion in hours rather than months. Add tested backups and a rehearsed incident-response plan and you have covered the fundamentals. For schools, our specialist education support is built around these realities, including the DfE’s digital and technology standards and safeguarding duties.
Source: GalaxyWarden Threat Research, 26 July 2026.