Department for Education Cyberattack Steals 607,000 Records

Department for Education Cyberattack Steals 607,000 Records

Hackers stole about 607,000 records from England’s Department for Education. Here’s what information was taken, who may be affected, and how you can better protect yourself from phishing and fraud.

What Happened?

According to BBC News, hackers stole about 607,000 records from England’s Department for Education in a cyberattack reported on July 29, 2026.

The incident affected the DfE online help desk and the Turing Scheme portal, which supports funding for international education. The department contained the attack quickly and began working with the National Cyber Security Centre and National Crime Agency.

The DfE also reported the incident to the Information Commissioner’s Office, the UK data protection regulator.

Even basic contact details can help criminals create convincing phishing emails, texts, or calls. Many people also do not know their information was leaked in other breaches.

If you are unsure whether your information was leaked, automatic monitoring can help you spot problems earlier. Futureproof monitors your data for leaks 24/7 and helps you reduce scam risks with simple, clear steps.

Who Was Affected and What Information Was Leaked?

The 607,000 figure refers to records, rather than 607,000 confirmed individuals. Reports linked the records to government officials, school leaders, university staff, parents, and organizations.

The stolen information included names, job titles, phone numbers, and email addresses. The DfE described it as customer service contact information.

The department said bank details and other highly sensitive information were not taken. It currently considers the data protection risk to individuals low.

Check if your data is safe from scammers

Futureproof scans your data for leaks and shows exactly how to close security gaps — before scammers find them first.

Check my safety

How Hackers Reached the DfE Portals

The DfE has not publicly explained exactly how hackers entered the affected systems. Therefore, the specific security weakness remains unknown.

A group calling itself ExfilSquad claimed responsibility and posted samples of the stolen data online. Reports said the group demanded payment to prevent more information from being published.

Reports also said the DfE found no evidence of ransomware, which is harmful software that locks files or systems until money is paid.