Hackers broke into the Department for Education and walked away with around 607,000 records. If you run a school, this one’s worth five minutes of your time.

What was taken
- Phone numbers and email addresses belonging to individuals and organisations
- No bank details
- No other sensitive personal data
- The 607,000 figure is records, not individuals, so the real number of people affected is smaller
- Two systems were hit: the Turing Scheme portal (funds international study and work placements) and the DfE’s online help desk
- Both expected back to normal this week
- DfE has referred itself to the Information Commissioner’s Office
- Working with the National Cyber Security Centre and the National Crime Agency
- Officials say the risk to individuals is low and the attack was contained quickly
Why school leaders should care
Contact details might sound low stakes compared to financial data. They’re not.
- Stolen emails and phone numbers get used for phishing
- A message with a real name, a real email, and a plausible reason to contact you (a Turing Scheme query, a help desk ticket) is far more convincing than a random scam email
- This isn’t an isolated event. The government’s Cyber Security Breaches Survey found:
- 24% of further education institutions report a breach or attack at least weekly
- More than half of schools have reported an attack or breach in the last year
Worth doing now:
- Review password policies
- Run a quick refresher on spotting phishing emails
- Confirm staff know who to flag suspicious messages to
Message for staff
Keep it simple and calm:
- A data breach hit the Department for Education. Contact details were affected, not financial or sensitive information.
- If you get an unexpected email or call referencing the DfE, Turing Scheme, or a help desk ticket you didn’t raise, don’t click links or share details.
- Verify it directly with the sender through a known number or website first.
- Flag anything suspicious to [IT contact/name] straight away.
Message for parents
Keep it short:
- You may see news about a data breach at the Department for Education.
- No financial details or sensitive information were involved.
- The school’s own systems were not affected.
- If you get a message that seems off or asks you to click a link or share details, please check with us before responding.
The bigger picture
This breach was handled quickly and the data taken was limited. But it’s a reminder that schools sit inside a much larger system, and a breach anywhere in that system can land phishing attempts in staff and parent inboxes. Treat this as a nudge to check your own basics are solid, not just a headline to skim past.