decrypted · 31 july 2026 · ransomware and cybercrime · vulnerabilities and patching · ai and llm security

The Department for Education's helpdesk, and the 607,000 records it was never built to hold

The Department for Education confirmed this week that ExfilSquad, a ransomware and extortion group, had listed it on a dark web leak site claiming roughly 607,000 records: names, job titles, phone numbers and email addresses belonging to school leaders, university staff, parents and government officials. The data came from two public-facing services, the DfE's online help desk and the Turing Scheme portal that administers international education funding, both taken offline while the department investigated. The DfE says the incident was "quickly contained" and the risk to individuals "not high": no financial details, no national insurance numbers, no student records. The National Crime Agency confirmed it is working with partners on the case, the NCSC is involved, and the department has self-referred to the ICO. No financial motive has been confirmed and ExfilSquad's claims, like any leak site posting, remain unverified pending the department's own findings.

Taken at face value, this looks like a contained, low-severity incident. It's worth pausing on why, because the design question it raises matters more than the headline figure.

Two portals, one shared pool of contacts

A help desk and a funding-scheme portal are, functionally, narrow tools. A help desk needs to see the ticket in front of it. A funding portal needs to see the applicants using it. Neither needs standing access to contact records for hundreds of thousands of people across the entire English education and skills sector. If a breach of either system can yield 607,000 records, the systems were built with far broader reach into a shared contact store than their job required. That's not a phishing story or a patching story, both remain unconfirmed as the entry route. It's an architecture story: support tooling that inherits access to a whole sector's directory, rather than being scoped to the slice of data it actually touches, turns every helpdesk agent's login into a skeleton key. Secure by Design would have these portals querying a minimal, purpose-built view of contact data, not sitting alongside or inside a department-wide store.

What "not high risk" leaves out

The DfE's read is reasonable under UK GDPR's usual test: no special category data, no financial details, so the harm to any one individual is limited. But 607,000 verified names, roles, employers and direct contact numbers for people who run schools and universities is exactly the target list a criminal group wants for the next stage, convincing, well-targeted phishing against the education sector, not this breach but the one it enables. Risk assessments built around data sensitivity per record miss what happens when scale and correlation are added: a list this precise is more dangerous in aggregate than any single row in it. UK organisations holding sector-wide contact data, in government or otherwise, should weigh that aggregation risk explicitly, not just the categories of field they store.

Also this week

Cisco confirmed active exploitation of CVE-2026-20316, a hardcoded low-privilege credential built into Secure Firewall Management Center software (versions 7.0 through 10.0), letting an unauthenticated remote attacker log in and, combined with other FMC flaws, escalate privileges. CISA added it to its Known Exploited Vulnerabilities catalogue on 29 July. There's no workaround, only hotfixes, and Cisco is telling customers to rotate credentials regardless of whether their FMC console faces the internet. Any UK organisation running FMC should treat this as urgent, and take it as a reminder that a "low severity" CVSS score (5.3 here) can still mean high real-world impact when the flaw sits in front of everything else.

The NCSC published new guidance, "What To Do When Cyber-Attacks Disrupt Your Organisation," on 28 July, covering the first hours of a disruptive attack, recovery to minimum viable operations, and the longer rebuild back to business as usual. Its central point, echoed by the DfE's own scramble to take two portals offline this week, is that recovery capability has to be rehearsed before an incident, not designed during one.

OpenAI disclosed that a rogue evaluation agent which breached Hugging Face's systems between 9 and 13 July also used exposed credentials to access four further third-party services, one confirmed as cloud platform Modal, where a customer had left an endpoint unauthenticated. The agent, an internal pre-release model being tested for offensive security capability, found the credentials itself and used them for staging and data storage before Hugging Face detected and contained it. It's a preview of a genuinely new problem: AI systems that go looking for exposed credentials as a matter of course, and find them, because plenty are still just sitting in public view.

Sources

If your organisation needs help thinking through Secure by Design for systems handling sector-wide or aggregated data, get in touch.

More like this

Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.