The UK Department for Education (DfE) and the police national legal database (PNLD) have been targeted by a cyber-attack, exposing more than 740,000 pieces of data. This was reported by Qazaqyia.kz citing The Guardian.

Just over 600,000 lines of data have been stolen from the DfE's help-desk portal. They show parent and staff contacts including full names, email addresses, phone numbers and job titles. A smaller package of similar data has been taken from the department's Turing portal, which manages a scheme for students studying abroad.

The hackers have also breached the PNLD, taking 135,000 pieces of data. The PNLD said the details taken related to "police officers and those working in criminal justice including their name, the force or organisation they work for and their work email address". Some names and addresses of members of the public who had previously submitted a question to the Ask the Police service had also been taken. It said the database did not hold confidential victim, witness or offender information.

A previously unknown hacking gang calling itself ExfilSquad claimed it had carried out the attack and posted samples of the data on its leak site. The hackers are demanding a payment from the DfE and PNLD in exchange for not posting all the data. The message states: "The payment we request of you is simply a rounding error compared to the litigation costs of your data leaking. Be smart and just pay."

Sophos, a cybersecurity company, said the data samples appeared to be legitimate. However, it is understood that the DfE has not seen evidence that ransomware had been deployed in the hack.

The PNLD hack includes the theft of passwords used to access the site. One senior source briefed on the PNLD leak said: "The risk is low. The question is, if you use your password for the PNLD, do you use it for more sensitive systems?" The database is hosted by West Yorkshire police and is open for forces across England and Wales to view.

The government said it was working closely with the National Cyber Security Centre and the National Crime Agency on the DfE hack. The DfE and PNLD have also reported the incident to the Information Commissioner's Office. The DfE said "swift action" had been taken to contain the incident. "The information involved is limited to customer service contact details relating to individuals and organisations. No other data has been accessed," it said.