Cyber Attackers Take 607,000 Records From the Department for Education
Around 607,000 records were taken in a cyber attack on the Department for Education in England, affecting the Turing Scheme portal and the departmental help desk. The incident lands in a sector where more than half of schools reported an attack or breach in the past year.
Article record
Why it matters
What this means for organisations holding critical data
Around 607,000 records were taken in a cyber attack on the Department for Education in England, affecting the Turing Scheme portal and the departmental help desk. The incident lands in a sector where more than half of schools reported an attack or breach in the past year.
Hackers have obtained approximately 607,000 records in a cyber attack on the Department for Education (DfE) in England, as first reported by the BBC. The department has confirmed the incident and is working with the National Cyber Security Centre and the National Crime Agency.
What Happened
The data taken includes telephone numbers and email addresses relating to individuals and organisations. According to the DfE, it does not include bank details or other sensitive information. The department states that the 607,000 figure relates to the total number of records affected rather than the number of individuals.
Two services were affected: the Turing Scheme portal, which administers funding for international education, and the DfE online help desk. Both were expected to return to normal operation within the week. The DfE has referred itself to the Information Commissioner's Office.
A DfE spokesperson said: "We have robust processes in place to protect information and took swift action to contain this incident. The information involved is limited to customer service contact details relating to individuals and organisations. No other data has been accessed."
A National Crime Agency spokesperson said: "We are aware of an incident affecting the Department for Education and are working with partners to understand the circumstances and impact."
Why It Matters
Contact details are often described as low-risk data. In practice they are the raw material of the next attack. A verified list of email addresses and telephone numbers belonging to schools, colleges, scheme administrators and the people who work with them is a ready-made targeting list for phishing, smishing and impersonation of the department itself. Attackers who can credibly appear to be the DfE help desk have a very short route into school systems that hold far more sensitive records.
The scale also matters. Six hundred and seven thousand records is not an edge case in an obscure system. It is a central government department losing a large volume of operational contact data from services that the education sector is required to use.
The Wider Education Picture
Education is now one of the most heavily targeted sectors in the United Kingdom. The government's Cyber Security Breaches Survey 2025 to 2026 found that around a quarter of further education institutions (24 per cent) experienced a breach or attack at least weekly, and that more than half of schools reported an attack or breach in the past year.
The threat is not only external. The Information Commissioner's Office has warned that children are hacking their own schools, often for status or entertainment rather than money, using credentials that are shared, guessed or simply watched over a shoulder.
The Firevault View
Every service that must stay online will eventually be probed, and some of those probes will succeed. The question that matters for a department, a trust or a single school is what remains recoverable and unreadable when that happens.
Offline Secure Storage answers that question at Layer 1. Records placed in an offline vault are physically disconnected from the network, so they cannot be read, altered, encrypted or exfiltrated by an attacker who is already inside an online estate. Safeguarding files, special educational needs records, pupil photographs, historic admissions data and governance papers do not need to be permanently reachable from the internet in order to be useful.
For a practical checklist aimed at schools and trusts, read our briefing on safeguarding education data in schools, colleges and universities.
Sources
- BBC News, "Cyber-attackers take 607,000 records from Department of Education"
- Department for Science, Innovation and Technology, Cyber Security Breaches Survey 2025 to 2026: education institutions findings
How Firevault would handle this
Physical disconnection removes the path an attacker needs
Offline Secure Storage® holds a clean copy of your data on hardware that is physically disconnected, so an intrusion cannot reach it, encrypt it or delete it.






