Hackers have successfully carried out a significant cyber intrusion on the Department for Education (DfE), resulting in the theft of over 600,000 pieces of data. The breach, which occurred last week, compromised 607,000 records containing personal information such as names, job titles, phone numbers, and email addresses of government officials, school administrators, and university personnel.
Despite the large number of records stolen, the Department clarified that the actual number of individuals affected may differ. Prompt action was taken by the DfE to contain the breach and mitigate potential data protection risks to the individuals involved.
The cyber attack targeted the Turing Scheme portal, a program supporting international education funding, and the department’s online help desk. As a precautionary measure, the DfE has temporarily shifted to using telephone services while addressing the security vulnerabilities.
In response to the incident, the Department is collaborating closely with the National Cyber Security Centre and the National Crime Agency, and has officially reported the breach to the Information Commissioner’s Office. Reports suggest that a group known as ExfilSquad has claimed responsibility for the breach.
A spokesperson from the DfE reassured the public, stating, “We have robust measures in place to safeguard information and acted swiftly to contain this breach. The compromised data is limited to customer service contacts and does not include other sensitive information.”
Paul Whiteman, the general secretary of the school leaders’ union NAHT, expressed concern over the reports, emphasizing the importance of clarifying the extent of the information accessed and ensuring that necessary steps are taken to prevent future breaches. Cybersecurity incidents can have serious repercussions, and it is essential for the Department to investigate thoroughly and provide reassurance to the affected parties.

