Hackers recently targeted the Department for Education (DfE) in a significant cyber intrusion, resulting in the theft of over 600,000 pieces of data. The breach, which occurred last week, compromised 607,000 records containing names, job titles, telephone numbers, and email addresses of government officials, school administrators, and university staff.
While the number of individuals affected by the breach does not directly correlate to the stolen data, the DfE confirmed that the breach was swiftly contained, minimizing the data protection risk to individuals. The attack primarily targeted the Turing Scheme portal, a platform for international education funding, and the department’s online help desk. As a precautionary measure, the DfE has temporarily shifted to telephone services while addressing the security vulnerabilities.
Collaborating with the National Cyber Security Centre and the National Crime Agency, the DfE has reported the incident to the Information Commissioner’s Office. The breach has been attributed to a group known as ExfilSquad, as per reports from The Times.
A spokesperson from the DfE assured that the compromised information was limited to customer service contact details and emphasized that no other data was accessed. Ongoing efforts are focused on working closely with cybersecurity agencies to mitigate any potential risks.
Paul Whiteman, general secretary of the school leaders’ union NAHT, expressed concerns over the breach, urging the DfE to promptly clarify the extent of the accessed information and reassure the public of preventive measures. The incident underscores the importance of thorough investigations to prevent future breaches and maintain sector-wide cybersecurity.
