Data Breaches

← Breach overview
Department for Education logo

Department for Education

education.gov.uk
🏛️Government & EducationDfE

The Department for Education (DfE) is a department of the UK government responsible for children’s services and education. It operates across the United Kingdom.

Key Takeaways

  • In July 2026, a cyberattack on the Department for Education exposed 607,000 records, including names, job titles, email addresses, and phone numbers.
  • This incident is part of a broader pattern of cyberattacks targeting government entities in the UK, with another police database also affected by the same group.
  • Individuals whose data was exposed should be vigilant about phishing attempts and unsolicited communications that leverage their professional information.

Breach Overview

In July 2026, the Department for Education (DfE) experienced a data breach that exposed approximately 607,000 records. The exposed data includes full names, job titles, telephone numbers, and email addresses. The affected individuals are primarily head teachers, senior school leaders, university staff, and government officials who interacted with the DfE's help desk portal and the Turing Scheme portal. The DfE has publicly acknowledged the incident and stated that the breach was limited to customer service contact details, with no other data accessed. The company has self-referred to the Information Commissioner's Office and is working with the National Crime Agency (NCA) and the National Cyber Security Centre (NCSC).

Exposed Data

Email addressesJob titlesNamesPhone numbers

Timeline & Cause

The breach occurred on July 26, 2026, and was disclosed on July 29, 2026. The attacker, known as ExfilSquad, breached the DfE's help desk portal and the Turing Scheme portal through a social engineering attack. Following the incident, affected systems were taken offline, and the department switched telephone communications as a precaution.

Next Steps

The exposed names, job titles, email addresses, and phone numbers could be used by attackers for highly targeted phishing emails or phone calls. These communications might impersonate the DfE or other trusted entities to trick individuals into revealing more sensitive information, clicking on malicious links, or downloading harmful software. Be extremely cautious of any unsolicited emails or calls, especially those asking for personal details or directing you to unfamiliar websites. The DfE has not provided specific remediation guidance, but it is advisable to verify the legitimacy of any unexpected communications by contacting the sender through official channels, not using contact information provided in the suspicious message itself.

Take Action