Department for Education data leaked on dark web

Hackers have stolen over half a million records from the Department for Education (DfE) in an attack confirmed by the department.

Approximately 607,000 lines of data were stolen from the Dfe’s online help desk and the Turing Scheme portal, used to fund study and work abroad placements.

A hacking group calling itself ExfilSquad claimed responsibility for the leak, first reported by the Times. The newspaper confirmed the names and email addresses of head teachers were among leaked data it was able to access on the dark web, adding that similar details on government officials and university staff have also been exposed.

The data protection risk to individuals impacted by the leak is not considered high and the exposed helpdesk data includes sets that cannot be connected to one another.

The DfE told National Technology News it is working closely with the National Cyber Security Centre and National Crime Agency in response to the incident.

“We have robust processes in place to protect information and took swift action to contain this incident,” a DfE spokesperson said.

“The information involved is limited to customer service contact details relating to individuals and organisations. No other data has been accessed.”

The DfE has also reported the incident to the Information Commissioner’s Office.

Graeme Stewart, head of public sector at Israeli cybersecurity company Check Point, said the hack was a reminder that hackers see government departments as high-value targets, with names and email addresses feeding directly into phishing campaigns.

“The fact that this follows other recent breaches across the public sector, including the Foreign Office attack last year, shows a pattern rather than a one-off failure,” he said.

“Departments need to treat help desks and third-party support systems as high-risk attack surfaces, not just back-office admin tools, because that's clearly where attackers are focusing their efforts. With the NCSC reporting a steep rise in nationally significant attacks, this can't be treated as an isolated incident. It should prompt a wider review of how sensitive contact data is stored, segmented and monitored across government IT estates."

Hackers are also targeting the education system directly. In the government’s latest cyber security breaches survey, 24 per cent of further education institutions and 29 per cent of higher education institutions reported experiencing a breach or attack at least weekly.



Share Story:

Recent Stories


The future-ready CFO: Driving strategic growth and innovation
This National Technology News webinar sponsored by Sage will explore how CFOs can leverage their unique blend of financial acumen, technological savvy, and strategic mindset to foster cross-functional collaboration and shape overall company direction. Attendees will gain insights into breaking down operational silos, aligning goals across departments like IT, operations, HR, and marketing, and utilising technology to enable real-time data sharing and visibility.

The corporate roadmap to payment excellence: Keeping pace with emerging trends to maximise growth opportunities
In today's rapidly evolving finance and accounting landscape, one of the biggest challenges organisations face is attracting and retaining top talent. As automation and AI revolutionise the profession, finance teams require new skillsets centred on analysis, collaboration, and strategic thinking to drive sustainable competitive advantage.