
The cyber-criminal group ExfilSquad has leaked the names and contact details of more than 100,000 police staff on the dark web.
The news follows threats from the same group last week to leak more data unless public institutions met their demands for payment. ExfilSquad posted on X:
Check your emails! We warned most of you before posting these public warnings!!
Once your company’s data is posted here, it’s NEVER leaving the public eye and it will be passed around the internet FOREVER.
The payment we request of you is simply a rounding error compared to the litigation costs of your data leaking. Be smart and just pay.
Hackers put multiple organisations under threat
Last week, the Canaryreported that the same hackers had posted data stolen from the Department for Education (DfE) and the Police National Legal Database (PNLD). A source explained that a majority of the 145,550 full-time police officers employed in England and Wales have used the PNLD as part of their daily work.
Whilst ExfilSquad stated that they targeted 14 institutions in total, the identities of the others were not public knowledge. However, the most recent reporting from the Telegraph has revealed that the wide-scale hack targeted the Crown Prosecution Service, Home Office, Ministry of Defence and the National Crime Agency.
Likewise, the cyber criminals also breached Newcastle University — the only non-state body named so far. ExfilSquad reportedly stole data including the names, addresses and phone numbers of both staff and students.
The university has already begun an investigation into the exact nature of the attack and the vulnerability of its systems.
Cybersecurity adviser Jake Moore, of European infosec giant Eset, explained:
The information put on the dark web should not be underestimated. More experienced threat actors see it as highly valuable because it enables them to personalise follow-up attacks, such as phishing or social engineering, which puts even more data at risk.
***
These attacks are becoming more common as criminals increasingly automate their tactics with ease and exploit the development using AI. The knock-on effect means organisations are facing a far higher volume of attacks, often with far less effort required from the attacker.
‘Officers at serious risk’
The Times reported that a government spokesperson declined to comment on the security breach, stating:
We have dedicated capabilities to respond to cyber incidents, and it would be inappropriate to comment on a live investigation.
However, a staff member from one of the targeted law enforcement organisations said:
I have worked in serious organised crime and put high-level criminals behind bars. For private information to be leaked about me is very disconcerting and puts officers at serious risk.
In the past I have been forced to move into safe houses and sell cars due to my job. Now I will have to keep my wits about me online and look out for anyone trying to get more serious information. It is not a good look.
Featured image via Ethan Wilkinson/ Unsplash
By Grace
From Canary via This RSS Feed.


