GCS Threat Briefing
Threat Landscape

No encryption. No ransomware. No way out.

G
Jonathan Garzon
Founder & CEO, Garzon Cyber Solutions
6 August 2026 · 6 min read

A single threat group has walked out of two UK government estates with more than 700,000 records, and neither incident has been confirmed as involving ransomware. With a public sector payment ban approaching, the old playbook has expired.

Executive Summary

  • An extortion group operating as ExfilSquad has claimed breaches at the UK Department for Education and the Police National Legal Database within a fortnight.
  • The DfE breach was executed through social engineering against an external-facing helpdesk, not a software vulnerability. More than 600,000 records were taken. PNLD has not publicly disclosed a root cause.
  • PNLD has confirmed that names, organisations and work email addresses of police officers, staff and criminal justice professionals were published on the dark web. No passwords or credentials are believed to have been compromised.
  • Neither incident has been confirmed as involving ransomware. The leverage is reputational, not operational.
  • The UK is moving to prohibit ransom payments across the public sector and critical national infrastructure. For a growing set of organisations, paying will not be an option, which changes the entire economics of preparedness.

What happened

On 26 July 2026, the Police National Legal Database identified what it later described as a data security incident. PNLD is not a peripheral system. Managed by West Yorkshire Police, it has operated as a legal reference platform for more than three decades and now serves all 43 Home Office police forces in England and Wales, alongside the British Transport Police, the Crown Prosecution Service, the Independent Office for Police Conduct and His Majesty's Courts and Tribunals Service.

In a statement on 3 August, PNLD confirmed that the names, organisations and work email addresses of police officers, staff, criminal justice professionals, government partners and customers had been compromised and published on the dark web. Names and email addresses of members of the public who had used its Ask the Police service were also affected. PNLD stated there is no evidence that passwords or security credentials were taken, and that the database holds no confidential information on victims, witnesses or offenders. The ICO has been notified and the National Crime Agency is assisting. ExfilSquad claimed responsibility, alleging it holds 1.9GB of data comprising approximately 135,000 records. These figures are the threat actor's claims and have not been confirmed by PNLD.

Five days before PNLD went public, the Department for Education disclosed its own breach. Computer Weekly reported that ExfilSquad had targeted an external-facing helpdesk used by school, university and local authority staff through a social engineering attack, taking more than 600,000 records containing full names, email addresses and telephone numbers of government and university staff and senior school leaders. The DfE stated the data was limited to customer service contact details and that it acted swiftly to contain the incident. Several systems were pulled offline. The department is engaged with the ICO, the NCA and the NCSC.

Timeline infographic showing four events in the ExfilSquad campaign: intrusion detected at PNLD on 26 July 2026, with root cause not publicly disclosed; the Department for Education confirming on 29 July that over 600,000 records were taken via a social engineering attack against a helpdesk, with systems pulled offline; PNLD publicly confirming on 3 August that names, organisations and work emails of justice staff were published, with ICO and NCA notified; and ExfilSquad on 3 August claiming 1.9GB and 135,000 records and seeking payment not to release the remainder. A footnote states the record figures are threat-actor claims unconfirmed by PNLD.
Two UK government estates compromised within a fortnight. The DfE vector was social engineering rather than a software exploit; PNLD has not disclosed a root cause. Record counts claimed by ExfilSquad are unverified by PNLD.

Why this matters commercially

It is tempting to file this under public sector news. That would be a mistake. Three shifts apply directly to enterprise and scale-up boards.

1. The service desk is now a primary attack surface

The DfE was not breached through an unpatched appliance or a zero-day. It was breached through a helpdesk process. Service desks exist to be helpful under time pressure, which makes them structurally vulnerable to a convincing request. Most organisations have spent a decade hardening perimeters and endpoints while leaving identity verification at the service desk to human judgement.

This is a control gap with a direct commercial cost, and among the cheapest to close. Out-of-band verification before any credential reset is a process change, not a capital programme.

2. Extortion has decoupled from encryption

Neither incident has been confirmed as involving ransomware. There is no evidence of encryption, no operational outage to recover from, and therefore no backup strategy that helps. The leverage is entirely reputational and regulatory.

The 2026 IBM Cost of a Data Breach Report, published on 29 July and based on 602 organisations, puts the global average breach cost at a record $4.99m, up 12% year on year. Notably, 41% of ransomware victims reported that attackers used the threat of brand reputation damage as the pressure lever. IBM's own framing is direct: the report describes "a move away from purely technical disruption toward multilayered extortion strategies that target trust, public perception and long-term business impact."

If your board's cyber resilience narrative is built on recovery time objectives, it addresses a threat model the market has already moved past.

"Calling in the NCSC and the NCA after a breach is damage control, not a security strategy." Jamie Moles, ExtraHop, quoted in Computer Weekly

3. Paying is becoming illegal, not just inadvisable

The Home Office has confirmed its intention to prohibit ransom payments across the public sector and operators of critical national infrastructure, including the NHS, local councils and schools. Around three-quarters of consultation respondents backed the proposals. Alongside the ban sits a mandatory incident reporting regime with an initial report expected within 72 hours.

For organisations in scope, the negotiation option disappears. For everyone else, supply chain contracts and insurer expectations will transmit the same standard downstream. The strategic consequence is straightforward: resilience that cannot be purchased during an incident must be purchased in advance.

Statistics infographic with six figures: over 600,000 Department for Education records exfiltrated including names, emails and phone numbers of officials, headteachers and university staff; over 100,000 police and justice contacts leaked across all 43 Home Office forces, British Transport Police, CPS, IOPC and HMCTS; $4.99 million average cost of a breach in 2026, a record high up 12 percent year on year across 602 organisations; 41 percent of ransomware victims pressured by brand damage rather than downtime; $1 million added cost per breach in AI-driven attacks; and a proposed 72-hour UK incident reporting window.
The commercial case in six figures. Breach cost data from the IBM Cost of a Data Breach Report 2026; reporting window from UK Home Office ransomware proposals.

What leaders should do now

These are actions that can be initiated inside 30 days and evidenced to a board, an auditor or an insurer.

  1. Harden identity verification at the service desk. Mandate out-of-band verification before any password reset, MFA re-enrolment or access change. Test it with a live social engineering exercise, not a policy review.
  2. Map where your identity data actually lives. Directories, CRM records, helpdesk ticketing and support portals hold the raw material for the next attack. Classify them as crown jewels.
  3. Rehearse a no-payment scenario. Most incident response plans quietly assume the option exists. Establish who decides, on what evidence, within what hours.
  4. Pre-agree the disclosure position. Draft regulator notifications and holding statements before the incident. The 72-hour clock is not the moment to start writing.
  5. Brief the exposed population immediately. As Dray Agha of Huntress observed, exposing names and work emails hands criminals a ready-made directory for spear-phishing against the very people defending the justice system. The same logic applies to your finance, legal and executive teams.
  6. Extend controls into the supply chain. Your supplier's helpdesk is your attack surface. Make verification standards and notification timelines contractual, and audit against them.
  7. Get reporting-ready. Build the logging, evidence chain and escalation path to file a credible report within 72 hours. This is a capability, not a document.
Board checklist infographic titled Seven moves for the next 30 days: harden the service desk with out-of-band verification before any credential reset or access change; map where identity data sits across directories, CRM and helpdesk systems and treat them as crown jewels; rehearse a no-pay scenario by testing the decision path assuming payment is not available; pre-agree the disclosure position with legal, comms and regulator notices drafted in advance; brief the exposed population because a leaked corporate directory is a ready-made spear-phishing kit; extend controls to third parties by contracting for them and auditing; and get reporting-ready for 72 hours by building the logging and evidence chain now. A closing panel introduces Garzon Cyber Solutions.
A board-ready checklist. Each item is evidenceable to an auditor, insurer or regulator within a single quarter.

The strategic read

The uncomfortable truth in this campaign is how ordinary the tradecraft was, at least where it has been disclosed. No novel exploit, no nation-state capability, no confirmed encryption. A convincing approach to a helpdesk, and a data set that turned into leverage.

That is good news, commercially. It means the controls that matter here are process controls, and process controls are cheap relative to the exposure they close. The organisations that will absorb this shift without material loss are the ones treating security as a governance capability rather than a technology purchase, and doing so before an incident forces the conversation.

Where GCS fits

Garzon Cyber Solutions advises boards and executive teams on cyber strategy, GRC, security assessments and AI governance, with a consulting model built around commercial outcomes rather than product volume. If you have not tested your service desk exposure, your third-party risk position or your readiness for the incoming UK reporting regime, that is a conversation worth having.

Arrange a conversation →

Sources

  1. ExfilSquad hackers leak info of over 100,000 UK police officers, staff, BleepingComputer, 3 August 2026.
  2. UK's Police National Legal Database Reveals Data Breach, Infosecurity Magazine, 4 August 2026.
  3. Department for Education suffers data breach, Computer Weekly, 29 July 2026.
  4. Police National Legal Database confirms data theft after dark web leak, The Register, 3 August 2026.
  5. UK police legal database breach exposes details of more than 100,000 officers and staff, Computing, August 2026.
  6. The Average Cost of a Data Breach Rises to $5 Million, Infosecurity Magazine, reporting on the IBM Cost of a Data Breach Report 2026, 29 July 2026.
  7. UK government to bring in ransomware payment ban, Computer Weekly, 2026.
  8. Ransomware payments ban to be introduced in the UK, Pinsent Masons, 2026.
  9. UK Education Department confirms breach as hacker gang leaks 600K records, Cybernews, July 2026.
  10. The DfE leak was first reported by The Times, 29 July 2026, as credited by Computer Weekly.
#Cybersecurity #DataBreach #Extortion #UKPublicSector #IncidentResponse #GRC #GarzonCyberSolutions

Garzon Cyber Solutions delivers cybersecurity advisory, compliance certification, and specialist technology recruitment as one integrated capability.