A cyberattack on the Department for Education has exposed more than 607,000 records containing personal contact details of headteachers, academy leaders, university staff and government officials, in one of the largest known data breaches to hit the UK education sector.
More than 607,000 records linked to the Department for Education’s customer support systems have been exposed in a major cyberattack, affecting headteachers, academy trust leaders, local authority staff, university employees and government officials. The breach has been claimed by a hacking group known as ExfilSquad, which is alleged to have published the stolen data on the dark web. The Department for Education said it acted immediately to take the affected systems offline, launch an investigation, and notify the Information Commissioner’s Office (ICO).
What was exposed
The leaked information is understood to include names, job titles, email addresses and telephone numbers belonging to a wide range of education-sector contacts, including government officials, school leaders, academy staff and university employees. Officials believe the stolen data primarily relates to people and organisations that had previously contacted or interacted with the Department for Education, rather than information relating to pupils or students themselves.
The attack is understood to have targeted two separate systems: the Department’s help desk platform and the Turing Scheme portal, which is used to manage UK students studying abroad. The Turing Scheme replaced the UK’s participation in the Erasmus+ programme following Brexit, and supports thousands of students, apprentices and learners studying overseas each year.
Scale of the breach
Given the range of those affected, spanning headteachers, academy trust leaders, local authority staff, university employees and Department for Education officials, the incident is being described as one of the largest known breaches involving the UK education sector. The Department has stated that the breach was limited to customer service contact information, and that there is currently no evidence that other government systems or datasets were compromised.
The response
The Department for Education said it contained the breach by taking the affected services offline shortly after the attack was discovered, and is continuing to notify affected organisations as its investigation progresses. The Department is working alongside the National Crime Agency (NCA) and the National Cyber Security Centre (NCSC) as part of the ongoing inquiry into the incident.
Risk of follow-on attacks
Cybersecurity experts have warned that even without financial information being exposed, the leaked contact details could still be used to carry out highly targeted phishing, impersonation and business email compromise attacks against schools and other education organisations. Such attacks typically rely on convincing, personalised communication rather than stolen financial data, making leaked contact information valuable to attackers in its own right.
Part of a wider trend
The incident comes amid a marked rise in cyberattacks targeting UK public bodies. According to the National Cyber Security Centre, the number of “highly significant” cyber incidents affecting the UK rose sharply from just one in 2022 to 18 in 2025, reflecting a substantial increase in serious attacks against public bodies and critical organisations.
Government cybersecurity surveys further show that 27% of further and higher education institutions report experiencing a cyberattack or security breach at least once a week, with phishing remaining the most commonly used method among attackers targeting the sector.
