The Department for Education (DfE) has confirmed a cyber‑security breach in which roughly 607,000 records were removed, primarily comprising contact information such as telephone numbers and email addresses linked to individuals and organisations that liaise with the department.
What was affected
Officials said two DfE systems were hit: the department’s online help desk and the portal used for the Turing Scheme, the UK programme that supports international study and placements. Both services were taken offline briefly but are expected to be restored to normal operation later this week.
- Data types taken: names, email addresses and phone numbers connected to customers of DfE services.
- Data not taken: no financial information, such as bank details, or other sensitive personal records were accessed.
- Scope: the figure of 607,000 refers to total records affected rather than unique people.
Official response and investigation
The department said it acted swiftly to contain the incident and is collaborating with national agencies. It has referred the matter to the Information Commissioner’s Office (ICO) and is working closely with both the National Cyber Security Centre (NCSC) and the National Crime Agency (NCA).
"We have robust processes in place to protect information and took swift action to contain this incident. The information involved is limited to customer service contact details relating to individuals and organisations. No other data has been accessed."
"We are aware of an incident affecting the Department for Education and are working with partners to understand the circumstances and impact."
Context for schools, colleges and universities
Cyber incidents in the education sector have been rising. Government survey data cited by the department shows a significant proportion of further education institutions report frequent breaches, and more than half of schools have experienced an attack or breach in the last year. That pattern underlines why prompt containment and national coordination are being emphasised.
| Item | Details |
|---|---|
| Records taken | 607,000 (contact records) |
| Services affected | Turing Scheme portal; DfE online help desk |
| Sensitive data | None (no bank details or other sensitive records) |
What parents, staff and governors need to know
Those who communicate with the DfE and use its services should be aware of the breach but not alarmed unnecessarily. Because the exposed information is contact details rather than financial or strongly identifying personal data, experts cited by the department judge the risk to individuals as low. Nonetheless, organisations and individuals should remain alert to potential phishing attempts that use legitimate names or addresses to appear credible.
- Be cautious of unexpected messages purporting to come from education departments or partners.
- Verify unusual requests for money or credentials by calling known official numbers rather than replying directly to emails or links received.
- Report suspicious contact to your institution’s IT lead and, where appropriate, to the ICO.
The DfE has said repairs and checks are underway and that telephone systems have been temporarily rerouted while maintenance continues. National agencies are investigating to establish how the breach occurred and to determine the full impact.