ExfilSquad: one hacker, three UK targets, three levels of confirmation
The ExfilSquad group claims 14 institutions, mostly British.
Three are documented here, with very different confirmation levels: the
police (officially widened scope), the Department for
Education (confirmed), and Wesco (confirmed, but downplayed).
β οΈ One actor, three targets, three different levels of
confirmation. ExfilSquad claims 14 institutions in total. This case file only
documents the three with sufficient detail and an official response β police, education,
and Wesco. The other eleven claimed targets remain publicly unidentified.
The numbers
135,000
Contacts claimed from the Police National Legal Database (PNLD) β
full names, professional emails, organizational affiliations. The scope was officially
widened to include the Ministry of Defence and the Home Office.
DataBreaches.Net, UKAuthority, August 3, 2026.
607,000
Records confirmed by the UK Department for Education itself: names,
job titles, phone numbers and emails of head teachers, university staff and government
officials.
Computer Weekly, IT Security Guru, July-August 2026.
2.6M
Rows claimed at Wesco, an international distributor. The company
confirms the incident but downplays its severity: no payment data affected, according
to the company.
ExfilSquad claim, incident confirmed by Wesco, not the exact
figure.
14
Institutions claimed in total by ExfilSquad. Only three are
documented here; the others remain publicly unidentified.
Group's claim, not verified as a whole.
Timeline
CONFIRMED
August 3, 2026
The Police National Legal Database (PNLD) leak, managed by West
Yorkshire Police, is revealed: roughly 135,000 contact records (police officers,
security staff, public agency workers). The scope is officially widened to include the
Ministry of Defence and the Home Office, in addition to the National Crime Agency and
Crown Prosecution Service. ExfilSquad publishes 1.9GB of compressed data and demands a
ransom.
CONFIRMED
Late July β August 2026
The Department for Education confirms a breach of 607,000
records from its Help Desk Self-Service Portal and Turing Scheme Portal: names, job
titles, phone numbers and emails of head teachers, university staff and government
officials. The incident is reported to the Information Commissioner's Office, in
coordination with the National Cyber Security Centre and the National Crime Agency.
CONFIRMED, BUT DOWNPLAYED
August 7-11, 2026
ExfilSquad begins distributing data presented as coming from
Wesco via torrents on August 7, following failed ransom negotiations. Wesco confirms
the incident on August 11 but states no business disruption occurred, no ransomware
was detected on internal systems, and that payment or financial data is not believed
to be at risk.
π―One actor, public and private, two countries
This case file illustrates an attacker profile not limited to one sector: the same
group hit a police database, a UK ministry, and a US industrial distributor. ExfilSquad
also targeted Analog Devices and Newcastle University according to the same sources. The
diversity of targets β public sector, education, supply chain β is itself a signal: this
isn't an actor specialized in one type of organization, but a group exploiting available
access wherever it finds it.
What it changes for you
If you are or were an employee of one of the named institutions β police, Ministry of
Defence, Home Office, Department for Education, Wesco β your name, role and professional
contact details could be in one of these leaks. The main risk is spear-phishing: a targeted
message relying on your exact job function to appear legitimate. See
From Leak to Scam.
π A professional message citing your exact job title or
institution deserves verification through an independent channel, especially if it demands
urgent action or sensitive information.
Frequently asked questions
Who is ExfilSquad?
A data-extortion and cybercrime group that emerged in 2026, claiming 14 UK and US
institutions; three are documented here.
Is the police legal database leak confirmed?
Yes, with its scope officially widened to include the Ministry of Defence and the
Home Office.
Did the UK Department for Education confirm its breach?
Yes, directly, with a report to the ICO and coordination with the NCSC and the
NCA.
π Last checked: August 23, 2026. Verifiable
information to report: contact@egidio.app.
Cite this pageEgidio β The Threat Laboratory, "ExfilSquad: one hacker, three UK targets, three levels of confirmation," egidio.app/en/laboratoire/exfilsquad-uk-campaign/. Licensed CC BY 4.0.
Free to reuse, including commercially, with attribution. Reuse terms.