The UK Department for Education confirmed on July 30, 2026 that attackers stole approximately 607,000 records from two of its external-facing systems — the department’s online customer help desk and the Turing Scheme portal, which administers funding for international study and training placements at schools, colleges and universities.

A threat group calling itself ExfilSquad claimed responsibility and is reported to have published the stolen data online.

It is one of the largest UK public sector breaches disclosed this year, and the DfE’s own framing of the number deserves attention: the department says 607,000 refers to individual lines of data, not individual people. That distinction narrows the headcount. It does not narrow the risk.

What Was Actually Taken

The stolen material includes:

  • Names
  • Job titles
  • Work email addresses
  • Telephone numbers

The records belong to individuals and organisations that had previously contacted the department — school leaders, university staff, college administrators and government officials.

The DfE confirmed no bank details or other financial information were among the material taken.

That is the reassuring half of the disclosure. The unreassuring half is what the field set actually is when you assemble it: a verified, current, role-annotated contact directory for the people who authorise spending across the English education system.

Why “No Financial Data” Understates This

A breach that exposes payment cards creates a bounded problem with a known remedy — reissue the cards. A breach that exposes name plus job title plus work email plus direct phone number, sourced from a government department’s own help desk, creates an unbounded one.

Consider what an attacker can now write. An email to a named business manager at a named academy trust, addressed correctly by role, referencing the Turing Scheme by name, arriving from a lookalike DfE domain, following up on a support ticket that genuinely existed. Then a phone call to the direct number in the record to “confirm” it.

Education is already the sector where this works. Higham Lane School lost two weeks to a shutdown in January. Great Marlow School closed during exam season in June. Schools and trusts typically run lean back offices, process large grant payments, and rarely have a dedicated security function. A high-fidelity target list handed to whoever downloads ExfilSquad’s dump is a durable problem measured in years, not in the weeks it takes to rotate credentials.

The Turing Scheme dimension makes it worse. That portal exists to move funding for overseas placements. Anyone impersonating it is impersonating a payment process.

The Systems Chosen

Both compromised systems were external-facing — a help desk and a public grant portal. Neither is a core departmental network holding pupil records, and the DfE has not indicated that anything deeper was reached.

This is the pattern that keeps recurring across the public sector. The crown-jewel databases get the segmentation, the monitoring and the audit attention. The citizen-facing web applications bolted on beside them — ticketing systems, funding portals, consultation sites, often delivered by external suppliers on separate infrastructure — accumulate years of contact data as a byproduct of doing their job, and inherit a fraction of the scrutiny.

Nobody designs a help desk as a data repository. It becomes one anyway, one ticket at a time, because deleting old tickets is nobody’s assigned responsibility.

Investigation

The DfE is working with the Information Commissioner’s Office, the National Cyber Security Centre and the National Crime Agency. The incident has been referred to the ICO.

ExfilSquad’s profile is thin. The name has surfaced in connection with data-theft-and-leak operations rather than encryption-based ransomware — the same extortion model that has displaced file encryption across much of the ecosystem, because publishing stolen records requires no decryptor, no negotiation infrastructure and no recovery for the victim to attempt.

Publication has reportedly already happened, which removes the only leverage the department had and confirms the practical outcome: the data is out, permanently, and the mitigation available to 607,000 lines’ worth of education professionals is vigilance.

Sources

  • UK Department for Education breach confirmation, July 30, 2026
  • Information Commissioner’s Office referral
  • Computing, DfE confirms cyber attack exposed 607,000 records
  • IT Security Guru, Experts react as Department for Education cyber attack exposes 607,000 records