Breach Analysis·29 July 2026

Cyber Attackers Take 607,000 Records From the Department for Education

Around 607,000 records were taken in a cyber attack on the Department for Education in England, affecting the Turing Scheme portal and the departmental help desk. The incident lands in a sector where more than half of schools reported an attack or breach in the past year.

Mark Fermor
Mark FermorDirector & Co-Founder, Firevault
3 min read
Share
Empty school corridor with lockers overlaid with a digital data grid, representing the Department for Education data breach
Breach Analysis

Article record

Breach AnalysisCategory
29 July 2026Published
3 min readReading time
Mark FermorWritten by
Empty school corridor with lockers overlaid with a digital data grid, representing the Department for Education data breach

Why it matters

What this means for organisations holding critical data

Around 607,000 records were taken in a cyber attack on the Department for Education in England, affecting the Turing Scheme portal and the departmental help desk. The incident lands in a sector where more than half of schools reported an attack or breach in the past year.

Hackers have obtained approximately 607,000 records in a cyber attack on the Department for Education (DfE) in England, as first reported by the BBC. The department has confirmed the incident and is working with the National Cyber Security Centre and the National Crime Agency.

What Happened

The data taken includes telephone numbers and email addresses relating to individuals and organisations. According to the DfE, it does not include bank details or other sensitive information. The department states that the 607,000 figure relates to the total number of records affected rather than the number of individuals.

Two services were affected: the Turing Scheme portal, which administers funding for international education, and the DfE online help desk. Both were expected to return to normal operation within the week. The DfE has referred itself to the Information Commissioner's Office.

A DfE spokesperson said: "We have robust processes in place to protect information and took swift action to contain this incident. The information involved is limited to customer service contact details relating to individuals and organisations. No other data has been accessed."

A National Crime Agency spokesperson said: "We are aware of an incident affecting the Department for Education and are working with partners to understand the circumstances and impact."

Why It Matters

Contact details are often described as low-risk data. In practice they are the raw material of the next attack. A verified list of email addresses and telephone numbers belonging to schools, colleges, scheme administrators and the people who work with them is a ready-made targeting list for phishing, smishing and impersonation of the department itself. Attackers who can credibly appear to be the DfE help desk have a very short route into school systems that hold far more sensitive records.

The scale also matters. Six hundred and seven thousand records is not an edge case in an obscure system. It is a central government department losing a large volume of operational contact data from services that the education sector is required to use.

The Wider Education Picture

Education is now one of the most heavily targeted sectors in the United Kingdom. The government's Cyber Security Breaches Survey 2025 to 2026 found that around a quarter of further education institutions (24 per cent) experienced a breach or attack at least weekly, and that more than half of schools reported an attack or breach in the past year.

The threat is not only external. The Information Commissioner's Office has warned that children are hacking their own schools, often for status or entertainment rather than money, using credentials that are shared, guessed or simply watched over a shoulder.

The Firevault View

Every service that must stay online will eventually be probed, and some of those probes will succeed. The question that matters for a department, a trust or a single school is what remains recoverable and unreadable when that happens.

Offline Secure Storage answers that question at Layer 1. Records placed in an offline vault are physically disconnected from the network, so they cannot be read, altered, encrypted or exfiltrated by an attacker who is already inside an online estate. Safeguarding files, special educational needs records, pupil photographs, historic admissions data and governance papers do not need to be permanently reachable from the internet in order to be useful.

For a practical checklist aimed at schools and trusts, read our briefing on safeguarding education data in schools, colleges and universities.

Sources

About the author

Mark Fermor

Mark Fermor

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

How Firevault would handle this

Physical disconnection removes the path an attacker needs

Offline Secure Storage® holds a clean copy of your data on hardware that is physically disconnected, so an intrusion cannot reach it, encrypt it or delete it.

HardwareYour data sits on dedicated encrypted hardware
DisconnectOffline by default, connected only when you say so
CommandAccess windows and retrieval under your control
LocationHeld in a secure Firevault Bunker

Share this article

Breach Analysis29 July 20263 min read

Cyber Attackers Take 607,000 Records From the Department for Education

Around 607,000 records were taken in a cyber attack on the Department for Education in England, affecting the Turing Scheme portal and the departmental help desk. The incident lands in a sector where more than half of schools reported an attack or breach in the past year.

Cyber Attackers Take 607,000 Records From the Department for Education
Mark Fermor
Published by Mark Fermor, Director & Co-Founder

    Your privacy matters

    We use cookies to keep the site running smoothly and to understand how you use it. You are in control. Privacy Charter · Cookie Policy