Skip to content
Social engineering attack hits DfE helpdesk systems

Social engineering attack hits DfE helpdesk systems

Ukauthority July 30, 2026

The Department for Education (DfE) has confirmed a data breach in which more than 607,000 records were stolen from its external-facing helpdesk, in an attack a threat group called ExfilSquad has claimed responsibility for

The stolen data includes full names, job titles, telephone numbers and email addresses of government officials, senior school leaders and university staff who had contacted the department. The Times , which broke the story, said it had seen names and email addresses of headteachers among data posted on the dark web.

The attack, understood to have taken place last week, targeted the DfE's helpdesk, which handles enquiries from school leaders and local authorities, and affected records held on the Turing Scheme, the database used to track UK students studying abroad. Computer Weekly reported that the breach was carried out via a social engineering attack on the helpdesk. The DfE said it took affected systems offline quickly to contain the incident.

The department has referred itself to the Information Commissioner's Office and is working with the National Crime Agency (NCA) and the National Cyber Security Centre (NCSC). A DfE spokesperson said: "We have robust processes in place to protect information and took swift action to contain this incident. The information involved is limited to customer service details relating to individuals and organisations. No other data has been accessed."

An NCA spokesperson said the agency was working with partners to understand the circumstances and impact of the incident.

The BBC reported that the 607,000 figure refers to the total number of records affected rather than the number of individuals, and that the data protection risk to those affected is not considered high. It added that no bank details or other sensitive financial information were taken. The Turing Scheme portal and the DfE helpdesk are expected to be operating normally again later this week.

Little is publicly known ExfilSquad. Computer Weekly reported that the group has also claimed responsibility for a separate, unconfirmed breach at Microsoft in recent days.

Cyber incidents affecting the education sector are becoming more common. According to the government's Cyber Security Breaches Survey 2025-26 , 27% of further and higher education institutions reported experiencing a breach or attack at least weekly, compared with 20% of secondary schools and 14% of primary schools, figures broadly unchanged on the year. Phishing was the dominant threat reported by colleges and universities.

The NCSC's most recent annual review recorded a rise in cyberattacks it classes as "nationally significant", from 63 in 2022 to 204 in 2025, and in those classed as "highly significant" - defined by their impact on central government or a large part of the population - from one to 18 over the same period. The review attributed part of the increase to the wider commercial availability of advanced cyber tools and to government dependency on third-party IT suppliers.

Extracted Entities

Attack Types (2)

Industries (1)

MITRE ATT&CK (1)