A Risk Assessment That Doesn't Add Up: Reading the DfE Breach

On July 29, the DfE confirmed hackers stole 607,000 records from its help desk and Turing Scheme portal. Names, emails and job titles of headteachers and senior leaders were among them. The DfE says the risk is "not high." That position needs challenging.

Share
A Risk Assessment That Doesn't Add Up: Reading the DfE Breach

The 60-second Briefing

  • On July 29, the DfE confirmed a cyberattack that exposed 607,000 records from its online help desk and Turing Scheme portal.
  • The stolen data includes names, job titles, work email addresses, and phone numbers of headteachers, senior school leaders, university staff, and government officials. It has been published on the dark web by a group calling itself ExfilSquad.
  • The DfE has referred itself to the ICO, NCA, and NCSC. No financial data or passwords were taken.
  • The DfE says the risk to individuals is "not considered high" because the stolen records cannot easily be linked. Cybersecurity experts strongly disagree.
  • The immediate risk is spear phishing against exactly the people who have institutional authority and safeguarding responsibility across the education sector.

On July 29, the Department for Education confirmed that hackers had stolen approximately 607,000 records from two of its external-facing systems: the online help desk that handles enquiries from school leaders and local authorities, and the Turing Scheme portal that administers overseas placement funding. A previously little-known group calling itself ExfilSquad claimed responsibility, and portions of the stolen data have already been published on the dark web.

The stolen records include names, job titles, work email addresses, and phone numbers of headteachers, senior school leaders, university staff, government officials, and anyone else who has contacted the DfE through those systems in recent years. The DfE has confirmed no bank details, passwords, or financial data were accessed. It has referred itself to the ICO, engaged the National Crime Agency and the National Cyber Security Centre, and stated that the overall risk to affected individuals is limited.

That last part is what I want to examine, because it is the point at which the department's official position and the operational reality of school IT begin to diverge.

The DfE's reasoning, according to statements it has made to Schools Week and The Times, is that the stolen data consists of separate sets that cannot easily be linked together, and therefore the data protection risk is not considered high. That is a defensible technical position for a data controller assessing its own liability. It is a much less defensible position for anyone with responsibility for the safety of school leaders whose contact details are now on a list circulating on the dark web.

Kevin Curran, senior IEEE member and professor of cybersecurity at Ulster University, put it more plainly in IT Security Guru: "This isn't just a data privacy incident; it's a ready-made list for spear phishing campaigns against people with meaningful access across the education sector." Jake Moore, global cybersecurity adviser at ESET, made the same point in The International Business Times: attackers routinely combine data from multiple breaches to construct detailed profiles before launching targeted attacks. The DfE's assessment considers each dataset in isolation. The attackers do not.

If a school leader's name, job title and work email address appeared in the DfE help desk or Turing Scheme portal at any point in recent years, that information is now on a public list. If they are a Head, a Deputy Head, a DSL, a DPO, an IT Director, a bursar, or anyone else in an institution that has ever raised a query with the department, that list has their name on it. The risk is not that the data breach will cause direct harm. The risk is that between now and the end of the calendar year, at least some of the people on that list will receive a highly targeted spear phishing email that appears to come from the DfE, the Turing Scheme, or a related institution, and that some of those emails will succeed.

This is the specific vulnerability my earlier posts pointed at. In A New Front Line: AI & 'The Com', I wrote about how organised cybercrime targets school leaders specifically because their credentials sit at the intersection of financial authority, safeguarding responsibility, and administrative access. In The 73% Problem, I set out the Cyber Security Breaches Survey, finding that phishing was the dominant attack vector in 96% of secondary school breaches. In The End of the Black Box, I argued that SLTs had to treat cyber as an institutional risk rather than something they could delegate to the IT function. The DfE breach is the empirical proof of all three arguments, provided by the department those arguments were partly directed at.

The timing matters. KCSIE 2026 activates on September 1. Schools are being asked to tighten safeguarding, mobile phone policy, AI-generated content responses, data protection under the DUAA, and volunteer vetting at exactly the moment when the wider institutional stack they depend on has demonstrated it can be breached. Nobody in school IT should enjoy watching a peer institution get hacked. But when the department writing the safeguarding guidance shows that it cannot protect its own customer service contact database, the argument that cyber is an institutional matter rather than an IT one becomes considerably harder to dodge.

There is practical work that needs to be done between now and the first day of term.

The first is a candid conversation with every senior member of staff whose email has ever appeared in DfE help desk or Turing Scheme correspondence. That is, in most schools, most of them. The message is short, and it needs to be repeated. For the next few months, treat any inbound email that appears to come from the DfE, the ICO, Ofsted, Ofqual, JCQ, ESFA, or any DfE-adjacent agency as potentially not from them. Verify the address. Verify the sender. Cross-check any request via an alternative channel. Assume the initial phishing attempts will be sophisticated because the attackers have real context to work with.

The second is a review of MFA and privileged access across the SLT, DSL and DPO group. Anyone with financial authorisation, safeguarding responsibility, or administrative access to core systems should be running MFA on every account. Where they are not, this is the moment. FIDO2 hardware keys, which I have written about before, are considerably more expensive than a password reset. They are also considerably cheaper than the aftermath of a successful spear-phishing attack on a Head's account.

The third is an update to the school's incident response plan. Every plan I have seen assumes the initial vector is unknown. The plans that will get tested in the next six months will not have that luxury. The DfE has, in effect, published a list of the people the attackers know are worth targeting. Any plan that does not account for the specific vector of a DfE-themed phishing email against a Head, a DSL or a DPO is a plan that needs updating this month.

The fourth is a broader question, and it is less a task than a discussion. If the department writing the digital and cyber standards has just demonstrated that it could not protect two of its own customer-facing systems, what does that mean about the wider stack schools depend on? The ICO's Edtech Examined report told us the EdTech suppliers had governance gaps. The DfE breach now tells us the department itself has operational gaps. The polite assumption that government-endorsed systems are safe by default has taken a serious knock, and procurement conversations that rested on that assumption should be revisited.

The DfE deserves credit for referring itself to the ICO, NCA and NCSC promptly and containing the incident before it spread further. That is the right response to a breach and, as Kevin Curran also noted, faster than many organisations manage. But faster than many is a different bar from good enough, and the sector conversation that follows this breach needs to hold both truths at the same time.

The wider threat picture has moved from theoretical to confirmed in ways that make previous concerns look prescient. As of May 2026, confirmed blackmail attempts against UK schools using AI-manipulated images of children have been reported. The Deepfake Threat written about in the spring is now an operational reality. The new front line described earlier in the year is not future tense. It is present tense.

None of this is cause for panic. It is cause for the boring, methodical work that IT and safeguarding teams have been arguing for for years. Verify. Enable MFA. Update the plan. Assume the initial phishing attempt is coming. If it is not, the school has lost a few afternoons of preparation time. If it is, and the school is ready, those few afternoons will look like the best investment of the entire summer.

See you in the digital staffroom.