This week’s cybersecurity and dark web news stories discuss a social engineering attack on UK DfE, cyberattack disrupting water utilities in Minnesota, and Bank of Baroda data leak.
ExfilSquad Hits UK Education
A previously unknown threat group called ExfilSquad is claiming two significant UK government breaches in the same week.
The Department for Education confirmed on July 29 that around 607,000 records had been stolen from two external-facing systems: its online customer helpdesk, used by school leaders, local authorities, and universities to contact the department, and the Turing Scheme portal, which administers overseas placements for UK students. The stolen data contains full names, job titles, work email addresses, and telephone numbers. No financial information was accessed. The DfE took affected systems offline quickly, referred itself to the Information Commissioner’s Office, and is working with the National Crime Agency and the National Cyber Security Centre. The department said the risk to individuals is considered low because the separate datasets cannot easily be linked into complete personal profiles.
But ExfilSquad didn’t stop there. The same week, the group claimed an attack on the Police National Legal Database, the system providing legal guidance to all 43 Home Office police forces in England and Wales – exposing around 135,000 records including contact details of serving officers, criminal justice workers, and members of the public. The Metropolitan Police confirmed the incident.
The immediate risk from the DfE breach, according to security experts, is follow-on spear-phishing. The dataset is effectively a high-quality directory of people with meaningful access across the UK’s education system, headteachers, university administrators, senior civil servants, built for targeting. The NCSC’s own annual review recorded a rise in nationally significant cyberattacks from 63 in 2022 to 204 in 2025. The attack on the DfE’s helpdesk via social engineering fits a pattern the agency has been warning about for years.
Thirty Minnesota Communities Wake Up to No Water as result of a cyberattack
On Sunday and Monday July 27 and 28, water treatment plants across more than 30 communities in Minnesota were knocked offline in what the state’s technology bureau has described as a coordinated cyberattack of undetermined origin. The victims ranged from Plymouth – a Minneapolis suburb of 80,000 people – to Braham, a town of 1,700 that brands itself the “Homemade Pie Capital of Minnesota,” which posted a notice asking residents to minimise water usage because the city tower held only a “limited quantity.” In every case confirmed so far, actual water quality was not affected – the attacks disrupted systems controlling water treatment and distribution, not the water itself.
Attribution hasn’t been confirmed, but the context points clearly in one direction. CISA and multiple federal agencies issued an urgent advisory last week warning about ongoing Iranian hacking groups – specifically CyberAv3ngers – targeting internet-connected operational technology devices including the programmable logic controllers widely used in water and wastewater facilities. Meanwhile, earlier in July, US strikes near the Strait of Hormuz destroyed an Iranian water facility, cutting supply to more than 20,000 people. The following day a group called Hanzala claimed to have accessed water utility systems in four California cities, warning Washington it had “restrained itself” from causing disruption – this time.
The structural problem underlying all of this is stark. The US has between 150,000 and 170,000 water utilities, many of them small, rural, and under-resourced. The EPA’s Office of Inspector General warned in 2024 that more than 70% were failing to comply with basic risk assessment requirements. An annual cyber drill this month – designed to test whether utilities could operate for a single day without their SCADA systems – saw what one researcher described as “a really tiny participation rate.” The same researcher noted that hospitals, which can exhaust their water reserves within two to four hours, depend on these utilities too. The consequences of a sustained disruption are not theoretical.
Bank of Baroda Data Extortion
On July 24, a data-extortion group calling itself TripleX listed Bank of Baroda – India’s second-largest public sector bank – on its dark web leak site, claiming to have exfiltrated roughly one terabyte of data and publishing it for free rather than holding it for ransom. Within 48 hours, independent cybersecurity researchers had verified samples of the material, and the bank had issued a statement.
Bank of Baroda confirmed on July 27 that a single employee’s email account had been compromised, allowing unauthorised access to certain files. The bank stated that its core banking systems – where accounts and transactions are processed – were not accessed and remain secure. A forensic investigation is ongoing. The bank has not confirmed the volume of data exfiltrated, the number of customers affected, or whether it met India’s mandatory six-hour incident notification window to CERT-In and the Reserve Bank of India.
What researchers who examined the sample files found is considerably more serious than a standard credential exposure. The dataset reportedly spans customer account-opening forms, estimated at between 100,000 and 300,000, many containing photographs and identity documents; Aadhaar and PAN numbers; savings, current, loan, and NRI account records; net banking user details; corporate banking records; branch audit reports; loan appraisal files; internal communications; and vigilance investigation documents. One researcher described it as “a cyber disaster.” The exposure of Aadhaar biometric identity numbers is a particular concern given their role as a foundational identifier across Indian financial and government services.
TripleX is a relatively new group, first observed in May 2026, and previously claimed a breach of PT Bank Negara Indonesia, one of Indonesia’s largest state-owned banks. The pattern is consistent: compromise through a single account, exfiltrate broadly, publish for free to maximise reputational damage. The lesson for financial institutions of any size is one the Bank of Baroda breach underlines sharply: one password, one inbox, and inadequate internal access controls should not be able to become one terabyte.