Hackers obtained around 607,000 records in a cyber attack on the Department for Education, including names, job titles, telephone numbers and email addresses of school leaders, government officials and university staff. No bank details or other sensitive information were accessed, and the DfE has referred itself to the Information Commissioner's Office.
TL;DR · LAST REVIEWED 30 July 2026
- A cyber attack on the Department for Education took around 607,000 records, a figure counting records rather than individuals.
- Data includes names, job titles, phone numbers and email addresses, but no bank details.
- The help desk and Turing Scheme portals were hit and moved to telephone service.
- The main risk for those affected is targeted phishing, and the DfE is working with the NCSC and National Crime Agency.
KEY FACTS
- Around 607,000 records were taken in a cyber attack on the Department for Education, counting records rather than individuals
- Stolen data includes names, job titles, telephone numbers and email addresses; no bank details were accessed
- School leaders, government officials and university staff are among those affected
- The DfE help desk portal and Turing Scheme portal were hit and have switched to telephone service
- The DfE has referred itself to the ICO and is working with the NCSC and National Crime Agency
What happened
The Department for Education has confirmed that hackers obtained around 607,000 records in a cyber attack understood to have taken place last week, targeting the department's external help desk portal and the Turing Scheme portal, which education providers use to manage funding for international placements. The stolen data includes names, job titles, telephone numbers and email addresses relating to individuals and organisations, with headteachers and senior school leaders, government officials and university staff among those affected, according to reporting. The department stresses two limits on the headline number: the 607,000 figure counts records rather than individuals, and the information involved is customer service contact details only, with no bank details or other sensitive information accessed. Reports based on dark web posts attribute the breach to a group calling itself ExfilSquad, and the attack is described as social engineering against the external-facing helpdesk rather than a technical compromise of core systems. The DfE says it took swift action to contain the incident, assesses the data protection risk to individuals as not high, and has referred itself to the Information Commissioner's Office while working with the National Cyber Security Centre and the National Crime Agency.
Who is affected and what the real risk is
The population affected is anyone whose contact details sat in the DfE's helpdesk system or the Turing Scheme database: school leaders who have contacted the department, staff at universities and colleges involved in international placement funding, and officials whose details appear in service records. The department has not said whether affected individuals have been directly informed, telling journalists only that it remains in contact with those affected. The realistic threat from this class of breach is not direct financial theft, since no bank details were taken, but targeted phishing: criminals who hold a person's name, job title, phone number, email address and the fact of their relationship with the DfE can construct convincing messages impersonating the department, the Turing Scheme, or IT support. Security analysts responding to the incident made exactly this point, warning that the exposure of headteachers and officials creates raw material for follow-on attacks by other criminal groups who buy or trade the data. Education is already among the most attacked sectors in the UK: the government's own Cyber Security Breaches Survey found around a quarter of further education institutions reporting a breach or attack at least weekly.
If your details may be involved
The defensive playbook for a contact-details breach is about scepticism rather than panic. Treat unexpected calls, emails and texts claiming to be from the DfE, the Turing Scheme, your multi-academy trust or IT support with heightened suspicion for the coming months, especially any message that references the breach itself, asks you to verify credentials, click a link to secure your account, or move to an urgent payment. Verify through known channels: contact the department through the phone routes on GOV.UK rather than numbers supplied in a message, and remember that legitimate organisations do not ask for passwords. School and university staff should be especially alert to invoice and payroll redirection attempts that name real colleagues, since job titles in the stolen data make internal impersonation easier. Enabling multi-factor authentication on work and personal email closes off the most damaging escalation path, and any phishing attempts should be forwarded to report@phishing.gov.uk, with suspicious texts forwarded to 7726. Anyone who suffers actual fraud should report it to Action Fraud and their bank immediately, where the reimbursement rules for authorised push payment fraud now require most banks to refund victims within days in qualifying cases.
The accountability picture
The DfE's self-referral to the Information Commissioner's Office triggers an independent assessment of whether the department met its data protection obligations, including the adequacy of the safeguards around an external-facing portal holding hundreds of thousands of contact records and the speed and clarity of notification to those affected. The department has history here: the ICO reprimanded the DfE in 2022 after poor due diligence allowed a screening firm to use a database of pupils' learning records for age checks on gambling accounts, a finding the regulator described in unusually blunt terms. School leaders' unions have pressed the department to say precisely what was taken and who has been told, with the NAHT noting that while school leaders' contact details are often public, the department owes those affected quick and clear reassurance. For individuals, the ICO route also carries personal rights: anyone who suffers damage from an organisation's data protection failures can complain to the ICO and, where loss results, seek compensation. The help desk and Turing portals remain on telephone service while remediation completes, with no published date for restoration. This article will be updated as the ICO's assessment and any notification to affected individuals develop. Related: our money guides, bills section, comparison guides and the latest UK news.
RELATED GUIDES
DISCLAIMER
This article is for general information only and does not constitute financial, legal or immigration advice. Figures and policy positions are correct at the time of writing and may change. Always check the relevant official source before acting.
Frequently asked questions
What data was stolen in the DfE cyber attack?
Names, job titles, telephone numbers and email addresses relating to individuals and organisations, across around 607,000 records. The DfE says no bank details or other sensitive information were accessed.
How do I know if my details were taken?
The DfE says it remains in contact with those affected but has not published a notification process. Anyone who has used the DfE help desk or Turing Scheme portal should treat unexpected DfE-related messages with caution.
What is the main risk from this breach?
Targeted phishing. Criminals holding your name, role and contact details can impersonate the DfE, the Turing Scheme or IT support convincingly. No bank details were taken, so direct financial theft from the data alone is unlikely.
Who is investigating the DfE breach?
The DfE is working with the National Cyber Security Centre and the National Crime Agency, and has referred itself to the Information Commissioner's Office, which assesses whether data protection obligations were met.
Can I claim compensation for a data breach?
If an organisation's data protection failures cause you damage, you can complain to the ICO and may be able to seek compensation, particularly where actual loss or distress results. Fraud losses should be reported to your bank and Action Fraud first.
SOURCES
- NCSC: Phishing guidance – accessed 30 July 2026
- ICO: Your data matters – accessed 30 July 2026
- GOV.UK: Cyber Security Breaches Survey – accessed 30 July 2026