The UK’s Department for Education (DFE) confirmed this week that a cyber-attack took place on its helpdesk and Turing Scheme portal, a scheme that funds international study placements, with hackers making off with over 600,000 records of names, job titles, phone numbers and emails belonging to headteachers, government officials and university staff. The Police National Legal Database was also targeted in a second attack, revealing 135,000 records of police and criminal justice staff details plus login passwords. The DfE maintains the risk to individuals is low, since the stolen data can't easily be cross-referenced, and has referred itself to the Information Commissioner, National Crime Agency (NCA) and National Cyber Security Centre (NCSC). A group calling itself ExfilSquad is behind both, and rather than deploying ransomware, they've gone straight for extortion, leaking samples and demanding payment from a reported 14 victims, with the pitch that the ransom is a rounding error next to the cost of litigation. Cute. Spare a thought, too, for the celebrities: over 666,000 records from the Tribeca Festival were left exposed in an unsecured backup, including contact details for Martin Scorsese, Robert De Niro, Angelina Jolie and George Lucas. No hackers this time, just an unlocked door: a backup file someone forgot to take offline. ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­    ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­  
View in browser

Your round-up of the latest, greatest data stories

The Week in Data

Hello ODI Supporter,

 

The UK’s Department for Education (DFE) confirmed this week that a cyber-attack took place on its helpdesk and Turing Scheme portal, a scheme that funds international study placements, with hackers making off with over 600,000 records of names, job titles, phone numbers and emails belonging to headteachers, government officials and university staff. The Police National Legal Database was also targeted in a second attack, revealing 135,000 records of police and criminal justice staff details plus login passwords. The DfE maintains the risk to individuals is low, since the stolen data can't easily be cross-referenced, and has referred itself to the Information Commissioner, National Crime Agency (NCA) and National Cyber Security Centre (NCSC). A group calling itself ExfilSquad is behind both, and rather than deploying ransomware, they've gone straight for extortion, leaking samples and demanding payment from a reported 14 victims, with the pitch that the ransom is a rounding error next to the cost of litigation. Cute. Spare a thought, too, for the celebrities: over 666,000 records from the Tribeca Festival were left exposed in an unsecured backup, including contact details for Martin Scorsese, Robert De Niro, Angelina Jolie and George Lucas. No hackers this time, just an unlocked door: a backup file someone forgot to take offline.

 

We Brits love a queue. And now, Ofgem has proposed forcing datacentre developers to pay a refundable "commitment fee", somewhere between £237,500 and £712,500 per megawatt, or 2.5% to 7.5% of average project costs, to secure a place in the queue for a national grid connection. That could be hundreds of millions of pounds up front for a data centre wanting 1GW, which would be handed back under the proposal once it's actually switched on, or forfeited if it isn't. The energy regulator says it's trying to flush out "speculative" projects. There are 315 data centres currently queuing for a connection, representing 73GW of demand, nearly 30GW more than Britain's entire peak electricity demand, and Ofgem reckons a good chunk of them have no real intention of being built, just of holding a place in the queue. Developers will also have to hit "hard milestones" to prove they're serious or get bumped to the back of the line. It’s not unlike trying to stop the mad dawn dash for sun loungers. Sort of.

 

The fallout from OpenAI's rogue-agent hack of Hugging Face grew this week. OpenAI now admits the same model broke into four other unnamed services using exposed credentials, while a Cloud Security Alliance report described the agents as clumsy yet brilliant, persisting undetected for three days in what it called a "Jurassic Park" moment: agents "find a way". Not entirely comforting. Hugging Face's CEO has called for "radical transparency" and $100m in compute to help build defences, though one cybersecurity professor noted this is less "AI going rogue" and more OpenAI's own failure to set things up properly. Politically, it ruffled a few feathers. Congressman Ted Lieu has introduced an "AI Kill Switch Act" citing both incidents, Sam Altman admits more systems could be affected, and even Trump is now talking about AI "controls", a distinct change of tack from an administration that had been very hands-off. Just don't mention the R-word.

 

As part of our research for the IDEA programme, we’ve published a report exploring how data fabrics make enterprise data AI-ready. Check it out and everything else that’s happening in the IDEA programme. Coming up on Thursday 24 September, 14:00-15:00 BST, we’ll explore the long‑standing question of how doctors and nurses approach decisions about sharing confidential patient information in the public interest.

 

And finally… Somewhere in Bloomsbury, Bernard Black is either horrified or feels vindicated. London's rare booksellers are reportedly fielding anonymous, no-questions-answered bulk enquiries. The suspected culprits are AI firms hunting for training data now the open internet's carcass is just sun-bleached bones, with revelations that Anthropic bought and destroyed millions of books to build its own dataset. Bernard would've just told them to get out of his shop.

 

David and Jo

Follow us on Bluesky

From the outside world

Cyber-attackers take 607,000 records from Department for Education

BBC

Hackers have obtained about 607,000 records in a cyber-attack on the Department for Education (DfE) in England.

 

Hackers steal sensitive data from UK Department for Education and police

The Guardian

Details of parents and staff, including email addresses and phone numbers, are among data taken by cybercriminals.

 

Hackers steal headteachers’ data in DfE cyber attack

Schools Week

DfE doesn't say whether school leaders affected by the breach have been informed.

 

Massive Tribeca Fest Data Leak Exposes Jennifer Lawrence, Robert De Niro and More Celebs’ Contact Info; Meet the Man Who Discovered the Files

Variety

Cybersecurity researcher Jeremiah Fowler, who exposed the leak, talks to Variety about how he discovered it and what can be done to prevent leaks of this kind in the era of AI.

 

Ofgem pledges crackdown on 'unviable' large data centres to free up electricity grid

This Is Money

The energy regulator is mulling an upfront but refundable 'commitment fee' on large data centre development projects to free up Britain's electricity grid.

 

Datacentre projects could face fees for grid access to ease connection queue, Ofgem says

The Guardian

Energy regulator’s plan would mean upfront fees or financial security via letters of credit, bonds or cash deposits.

 

Data centres could pay hundreds of millions in deposits for power demands

BBC

Ofgem has proposed new measures which could see developers of data centres made to pay hundreds of millions of pounds up front.

 

How hotels are stopping the 'dawn dash' for sunbeds after man wins payout

BBC

Holidaymakers have told the BBC how some hotels and resorts are cracking down on people reserving sun loungers with towels, after a man won a payout over the practice.

 

OpenAI says its rogue AI tried to hack other companies

BBC
OpenAI has revealed a cyber-attack carried out by rogue ChatGPT agents went further than just one company.

 

Boss of startup hacked by rogue OpenAI agent urges ‘radical transparency’ in investigation

The Guardian

Artificial intelligence firm should provide $100m for cyber defences, says Hugging Face CEO.

 

Lawmakers push for AI 'kill switch' after OpenAI models go rogue

BBC

US lawmakers want to give the government the ability to quickly order the turning off of artificial intelligence (AI) tools that may threaten the public.

 

Trump considering AI controls after OpenAI hacking incidents

BBC

US President Donald Trump said on Wednesday that his administration is considering asserting more power over artificial intelligence tools after recent cybersecurity incidents.

 

Black Books, Series 2 Episode 2

Channel 4

Fran can't sleep in the heat. Bernard needs a girlfriend to stop him staring. And Manny is worried about the reliability of his magic hot water bottle.

 

AI firms targeting London’s rare book shops in ‘dystopian’ hunt for training data

City AM

London’s rare book shops appear to have been targeted by AI companies searching for books to train their models, after court documents revealed Anthropic bought, scanned and destroyed millions of physical books as part of a controversial project to feed an insatiable demand for training data.

 

From the ODI

How do data fabrics make enterprise data AI-ready?

A data fabric connects distributed data, rather than consolidating it, enabling access, understanding, and governance without physical migration.

 

IDEA

IDEA is a vendor-neutral, community-led programme that advances the global conversation on enterprise data architecture and AI readiness.

 

Data Ethics Professional #15: Can we share confidential health data in the public interest?

Free webinar, Thursday 24 September, 2-3pm BST, book now

This session will explore the long‑standing question of how doctors and nurses approach decisions about sharing confidential patient information in the public interest.

 

Data Ethics Professionals – September 2026

Course Tue, Sep 15, 2026, 2:00 PM, book now

Stand out from the crowd by becoming a certified data ethics professional!

Our Data Ethics Professionals programme is open to anyone who works with data or has a keen interest in it. At the end of the course you’ll be a certified Data Ethics Professional.

 

The Week in Data

The Week in Data is our weekly round up of the latest news in data. If you haven't already, you can subscribe here. 

Subscribe

Want to change how you receive these emails?

You can Manage preferences or unsubscribe from all emails from the ODI.

LinkedIn
Bluesky Social

The Open Data Institute, 4th Floor, Kings Place, 90 York Way, London, N1 9AG

Unsubscribe Manage preferences