Three government hacks in one week: Has Whitehall learnt its lesson?
Trevor Dearing, Director of Critical Infrastructure at Illumio, argues that three government breaches in one week show why Whitehall must focus less on keeping attackers out and more on limiting the damage once they are inside.
In the space of a week in July, we saw three separate government departments, the Department for Education, the Ministry of Defence and the Home Office, all suffer data breaches at the hands of the ExfilSquad data extortion group. The result was thousands of records being leaked, including the Police National Legal Database (PNLD) and MoD employee data.
Now, I would like to say it’s shocking that a breach like this could ever happen, but then I would be lying.
In the past few years, we’ve witnessed data breaches against the Legal Aid Agency, the Electoral Commission and the Police Service of Northern Ireland. These are just a few of the major ones targeting public-sector entities; I could list plenty of others.
The bit that does surprise me is that even after all these incidents and years of warnings, the government sector is apparently still not learning its lesson. Attackers retain the ability to access such large volumes of sensitive data, and that, to me, suggests many departments remain too reliant on keeping attackers out rather than limiting what they can reach once they’re in.
The challenges facing government departments
One thing I should make clear from the start is that public-sector security is not easy. Public-sector organisations face significant cybersecurity barriers compared with their private-sector counterparts. Budget constraints, a familiar issue across most Civil Service departments, are particularly challenging.
Limited spending ability impacts both access to new security solutions and the hiring and development of staff. Combined with the size and complexity of public-sector departments, shifting to new strategies often has the laborious feeling of trying to turn a supertanker.
Modern government infrastructure is sprawling and interconnected, with applications, workloads, users and data sitting across multiple different environments. The reliance on third parties only aggravates the risk.
Many third-party suppliers do not adhere to the strict security standards required to protect sensitive government assets and information. While these suppliers might pass the initial vetting process, new vulnerabilities and risks can show up at any time.

The issue is that many government departments don’t have visibility into those risks. In May 2025, the Public Accounts Committee released a report which found that departments had self-identified 319 legacy systems, with around a quarter of those flagged as high risk, and even the Cabinet Office admits it doesn’t know the true scale beyond that.
This almost sums up the problem facing government departments and explains the latest attacks. A technical analysis of the PNLD data breach suggests that the likely attack vector was the exploitation of a misconfigured public-facing application.
Conducting regular audits and continuously monitoring these providers’ systems ensures that they comply with the necessary security protocols, thereby minimising potential vulnerabilities.
Departments’ approach to security is wrong
Whilst more audits and monitoring are good, government departments need to be addressing the root cause rather than just trying to fix systems.
Public-sector cyber contract values have surged dramatically, rising by more than 300% since 2020. However, the NCSC dealt with 204 ‘nationally significant’ cyberattacks against the UK in the 12 months to August 2025, rising from 89 in the previous year. So that shows there’s something wrong with our approach.
Of course, every public-sector organisation wants to avoid being the victim of a data breach and being back in the news again. It’s this mentality that puts them in this position because the assumption is to try to stop attackers from entering.
It might sound logical, but trying to stop every attack from breaching the perimeter is impossible. AI has made the odds even smaller, allowing attackers to discover misconfigurations, generate exploits and pivot laterally at machine speed. When adversaries operate faster than humans can respond, prevention becomes a probability game you can’t win.

The difference between a well-contained, managed incident and a front-page crisis has always been about what happens after the criminal has got in. The Home Office, for example, doesn’t mandate the police to prevent crimes before they happen. They accept there will always be criminals, so they try to reduce the risks and contain them when they happen.
The aim of government departments must be to restrict the ability of attackers to move within systems and reduce the impact of attacks. We found that nearly 90% of organisations have experienced security incidents involving lateral movement in the last 12 months.
And the public sector will experience the same issue. A single point of compromise cascades into wider disruption because systems weren’t separated from one another. When everything is flat and interconnected, one exploited vulnerability in one ageing system becomes a route into everything else.
Limiting what attackers can access once inside
The first priority is assessing the current capabilities, mapping the most critical risks and establishing protocols that allow rapid decision-making when attacks occur. This doesn’t mean generating more alerts or collecting more logs. That will only make things worse.
Government needs to understand which risks matter most, how they connect and where an attack is likely to spread. By leveraging AI and deep-network observability tools, security teams can cut through the noise to see real exposure and act before threats escalate.
The second priority is containing lateral movement. As mentioned before, this is what turns a minor disruption into a multimillion-pound crisis.
By proactively segmenting networks, isolating workloads and enforcing least-privilege access, departments can protect critical systems, isolate risky legacy infrastructure and force attackers to slow down. That friction exposes their activity sooner, reducing both dwell time and impact.
A strategy that doesn’t break the bank
Importantly, a containment-first approach fits into the government’s Cyber Action Plan, which is pushing for greater accountability, visibility, faster response, recovery and systemic risk management in the public sector.
Containment isn’t about ripping out every legacy system or cutting every third-party supplier, because that isn’t going to happen. It’s about changing the mindset adopted by government departments so that resilience is built by limiting damage, not by pretending it can always be avoided.
The public sector has had years of warnings and no shortage of breaches to learn from. The lesson has been sitting there the whole time. It’s time departments actually acted on it.
Sign up for our newsletter and get our latest content in your inbox.
Similar Reads
Sign up for our newsletter. Select all sectors relevant to you.
Related















