Hackers have stolen over half a million records from the Department for Education (DfE) in an attack confirmed by the department.
Approximately 607,000 lines of data were stolen from the Dfe’s online help desk and the Turing Scheme portal, used to fund study and work abroad placements.
A hacking group calling itself ExfilSquad claimed responsibility for the leak, first reported by the Times. The newspaper confirmed the names and email addresses of head teachers were among leaked data it was able to access on the dark web, adding that similar details on government officials and university staff have also been exposed.
The data protection risk to individuals impacted by the leak is not considered high and the exposed helpdesk data includes sets that cannot be connected to one another.
The DfE told National Technology News it is working closely with the National Cyber Security Centre and National Crime Agency in response to the incident.
“We have robust processes in place to protect information and took swift action to contain this incident,” a DfE spokesperson said.
“The information involved is limited to customer service contact details relating to individuals and organisations. No other data has been accessed.”
The DfE has also reported the incident to the Information Commissioner’s Office.
Graeme Stewart, head of public sector at Israeli cybersecurity company Check Point, said the hack was a reminder that hackers see government departments as high-value targets, with names and email addresses feeding directly into phishing campaigns.
“The fact that this follows other recent breaches across the public sector, including the Foreign Office attack last year, shows a pattern rather than a one-off failure,” he said.
“Departments need to treat help desks and third-party support systems as high-risk attack surfaces, not just back-office admin tools, because that’s clearly where attackers are focusing their efforts. With the NCSC reporting a steep rise in nationally significant attacks, this can’t be treated as an isolated incident. It should prompt a wider review of how sensitive contact data is stored, segmented and monitored across government IT estates.”
Hackers are also targeting the education system directly. In the government’s latest cyber security breaches survey, 24 per cent of further education institutions and 29 per cent of higher education institutions reported experiencing a breach or attack at least weekly.



.jpg)


