No encryption. No ransomware. No way out.
A single threat group has walked out of two UK government estates with more than 700,000 records, and neither incident has been confirmed as involving ransomware. With a public sector payment ban approaching, the old playbook has expired.
Executive Summary
- An extortion group operating as ExfilSquad has claimed breaches at the UK Department for Education and the Police National Legal Database within a fortnight.
- The DfE breach was executed through social engineering against an external-facing helpdesk, not a software vulnerability. More than 600,000 records were taken. PNLD has not publicly disclosed a root cause.
- PNLD has confirmed that names, organisations and work email addresses of police officers, staff and criminal justice professionals were published on the dark web. No passwords or credentials are believed to have been compromised.
- Neither incident has been confirmed as involving ransomware. The leverage is reputational, not operational.
- The UK is moving to prohibit ransom payments across the public sector and critical national infrastructure. For a growing set of organisations, paying will not be an option, which changes the entire economics of preparedness.
What happened
On 26 July 2026, the Police National Legal Database identified what it later described as a data security incident. PNLD is not a peripheral system. Managed by West Yorkshire Police, it has operated as a legal reference platform for more than three decades and now serves all 43 Home Office police forces in England and Wales, alongside the British Transport Police, the Crown Prosecution Service, the Independent Office for Police Conduct and His Majesty's Courts and Tribunals Service.
In a statement on 3 August, PNLD confirmed that the names, organisations and work email addresses of police officers, staff, criminal justice professionals, government partners and customers had been compromised and published on the dark web. Names and email addresses of members of the public who had used its Ask the Police service were also affected. PNLD stated there is no evidence that passwords or security credentials were taken, and that the database holds no confidential information on victims, witnesses or offenders. The ICO has been notified and the National Crime Agency is assisting. ExfilSquad claimed responsibility, alleging it holds 1.9GB of data comprising approximately 135,000 records. These figures are the threat actor's claims and have not been confirmed by PNLD.
Five days before PNLD went public, the Department for Education disclosed its own breach. Computer Weekly reported that ExfilSquad had targeted an external-facing helpdesk used by school, university and local authority staff through a social engineering attack, taking more than 600,000 records containing full names, email addresses and telephone numbers of government and university staff and senior school leaders. The DfE stated the data was limited to customer service contact details and that it acted swiftly to contain the incident. Several systems were pulled offline. The department is engaged with the ICO, the NCA and the NCSC.
Why this matters commercially
It is tempting to file this under public sector news. That would be a mistake. Three shifts apply directly to enterprise and scale-up boards.
1. The service desk is now a primary attack surface
The DfE was not breached through an unpatched appliance or a zero-day. It was breached through a helpdesk process. Service desks exist to be helpful under time pressure, which makes them structurally vulnerable to a convincing request. Most organisations have spent a decade hardening perimeters and endpoints while leaving identity verification at the service desk to human judgement.
This is a control gap with a direct commercial cost, and among the cheapest to close. Out-of-band verification before any credential reset is a process change, not a capital programme.
2. Extortion has decoupled from encryption
Neither incident has been confirmed as involving ransomware. There is no evidence of encryption, no operational outage to recover from, and therefore no backup strategy that helps. The leverage is entirely reputational and regulatory.
The 2026 IBM Cost of a Data Breach Report, published on 29 July and based on 602 organisations, puts the global average breach cost at a record $4.99m, up 12% year on year. Notably, 41% of ransomware victims reported that attackers used the threat of brand reputation damage as the pressure lever. IBM's own framing is direct: the report describes "a move away from purely technical disruption toward multilayered extortion strategies that target trust, public perception and long-term business impact."
If your board's cyber resilience narrative is built on recovery time objectives, it addresses a threat model the market has already moved past.
"Calling in the NCSC and the NCA after a breach is damage control, not a security strategy." Jamie Moles, ExtraHop, quoted in Computer Weekly
3. Paying is becoming illegal, not just inadvisable
The Home Office has confirmed its intention to prohibit ransom payments across the public sector and operators of critical national infrastructure, including the NHS, local councils and schools. Around three-quarters of consultation respondents backed the proposals. Alongside the ban sits a mandatory incident reporting regime with an initial report expected within 72 hours.
For organisations in scope, the negotiation option disappears. For everyone else, supply chain contracts and insurer expectations will transmit the same standard downstream. The strategic consequence is straightforward: resilience that cannot be purchased during an incident must be purchased in advance.
What leaders should do now
These are actions that can be initiated inside 30 days and evidenced to a board, an auditor or an insurer.
- Harden identity verification at the service desk. Mandate out-of-band verification before any password reset, MFA re-enrolment or access change. Test it with a live social engineering exercise, not a policy review.
- Map where your identity data actually lives. Directories, CRM records, helpdesk ticketing and support portals hold the raw material for the next attack. Classify them as crown jewels.
- Rehearse a no-payment scenario. Most incident response plans quietly assume the option exists. Establish who decides, on what evidence, within what hours.
- Pre-agree the disclosure position. Draft regulator notifications and holding statements before the incident. The 72-hour clock is not the moment to start writing.
- Brief the exposed population immediately. As Dray Agha of Huntress observed, exposing names and work emails hands criminals a ready-made directory for spear-phishing against the very people defending the justice system. The same logic applies to your finance, legal and executive teams.
- Extend controls into the supply chain. Your supplier's helpdesk is your attack surface. Make verification standards and notification timelines contractual, and audit against them.
- Get reporting-ready. Build the logging, evidence chain and escalation path to file a credible report within 72 hours. This is a capability, not a document.
The strategic read
The uncomfortable truth in this campaign is how ordinary the tradecraft was, at least where it has been disclosed. No novel exploit, no nation-state capability, no confirmed encryption. A convincing approach to a helpdesk, and a data set that turned into leverage.
That is good news, commercially. It means the controls that matter here are process controls, and process controls are cheap relative to the exposure they close. The organisations that will absorb this shift without material loss are the ones treating security as a governance capability rather than a technology purchase, and doing so before an incident forces the conversation.
Where GCS fits
Garzon Cyber Solutions advises boards and executive teams on cyber strategy, GRC, security assessments and AI governance, with a consulting model built around commercial outcomes rather than product volume. If you have not tested your service desk exposure, your third-party risk position or your readiness for the incoming UK reporting regime, that is a conversation worth having.
Arrange a conversation →Sources
- ExfilSquad hackers leak info of over 100,000 UK police officers, staff, BleepingComputer, 3 August 2026.
- UK's Police National Legal Database Reveals Data Breach, Infosecurity Magazine, 4 August 2026.
- Department for Education suffers data breach, Computer Weekly, 29 July 2026.
- Police National Legal Database confirms data theft after dark web leak, The Register, 3 August 2026.
- UK police legal database breach exposes details of more than 100,000 officers and staff, Computing, August 2026.
- The Average Cost of a Data Breach Rises to $5 Million, Infosecurity Magazine, reporting on the IBM Cost of a Data Breach Report 2026, 29 July 2026.
- UK government to bring in ransomware payment ban, Computer Weekly, 2026.
- Ransomware payments ban to be introduced in the UK, Pinsent Masons, 2026.
- UK Education Department confirms breach as hacker gang leaks 600K records, Cybernews, July 2026.
- The DfE leak was first reported by The Times, 29 July 2026, as credited by Computer Weekly.
Garzon Cyber Solutions delivers cybersecurity advisory, compliance certification, and specialist technology recruitment as one integrated capability.