Head teacher data accessed in Department for Education cyber attack

The incident highlights the continuing vulnerability of the education sector

Cybersecurity concept image showing padlock symbols on data storage blocks in a larger data storage array.
(Image credit: Getty Images)

The UK's Department for Education (DfE) has confirmed that hackers have accessed more than 600,000 records.

The data includes the names, job titles and phone numbers of thousands of head teachers, university staff and government officials. It was accessed via the DfE’s Help Desk Self-Service Portal and the Turing Scheme Portal, which handles students planning to study abroad.

According to The Times, the attack has been claimed by the new - and still shadowy - ExfilSquad hacking group, which has released the data on the dark web.

A DfE spokesperson told ITPro that the risk to individuals is low, and that the general helpdesk data breached includes different sets of data which cannot be connected. The 607,000 figure relates to the number of records, not the number of individuals affected, she added.

Latest Videos FromIT Pro

"We have robust processes in place to protect information and took swift action to contain this incident," she said.

"The information involved is limited to customer service contact details relating to individuals and organizations. No other data has been accessed."

The spokesperson said the department is now working closely with the National Cyber Security Centre (NCSC) and the National Crime Agency (NCA), and has reported the incident to the Information Commissioner's Office (ICO). It's working to fix both portals, and has switched to telephone contact in the meantime.

"Names and email addresses belonging to government officials, senior school leaders, and university staff is a high-value targeting dataset. These are people with institutional authority, access to sensitive systems, and in many cases responsibility for safeguarding student data," said Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress.

"In the wrong hands, this isn't just a data privacy incident, it's a ready-made list for spear phishing campaigns against people with meaningful access across the education sector."

Research late last year from Keeper Security found that 42% of UK educational institutions have already been targeted by AI-generated phishing attempts, with 93% at least somewhat concerned about AI-related cybersecurity threats.

Graeme Stewart, head of public sector at Check Point, said his firm's threat data shows that education is currently one of the most targeted sectors globally, facing thousands of attacks per organization every week. In the UK, as of June, it sat as the most frequently targeted industry.

"The fact that this follows other recent breaches across the public sector, including the Foreign Office attack last year, shows a pattern rather than a one-off failure. Departments need to treat help desks and third-party support systems as high-risk attack surfaces, not just back-office admin tools, because that's clearly where attackers are focusing their efforts," he said.

"With the NCSC reporting a steep rise in nationally significant attacks, this can't be treated as an isolated incident. It should prompt a wider review of how sensitive contact data is stored, segmented and monitored across government IT estates."

Emma Woollacott

Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.