The Department for Education has reported a cyber-attack that exposed about 607,000 contact records, mainly telephone numbers and email addresses. The DfE says no bank details or other highly sensitive data were accessed and has referred the incident to the Information Commissioner’s Office while working with the NCSC and NCA. Affected services — including the Turing Scheme portal and the online helpdesk — should be restored later this week. Officials described the risk to individuals as not high, and investigations and containment efforts are ongoing.
DfE Cyber-Attack Exposes About 607,000 Contact Records — No Bank Data Accessed

Hackers have obtained about 607,000 records from the Department for Education (DfE) in England, primarily containing telephone numbers and email addresses for individuals and organisations. The department says no bank details or other highly sensitive personal data were accessed.
Incident and Response
The DfE confirmed the breach and said it is working closely with the National Cyber Security Centre (NCSC) and the National Crime Agency (NCA). The department has also voluntarily referred the incident to the Information Commissioner’s Office (ICO).
"We have robust processes in place to protect information and took swift action to contain this incident," a DfE spokesperson said. "The information involved is limited to customer service contact details relating to individuals and organisations. No other data has been accessed."
Services Affected
The Turing Scheme portal — which provides funding for international education placements — and the DfE online helpdesk were affected by the attack. The DfE said both services are expected to be operating normally later this week.
Scope and Risk
The department emphasised that the figure of 607,000 refers to records affected, not necessarily distinct individuals. Officials said the data protection risk to individuals is not considered high and that the attack was contained quickly, but investigations with law enforcement and cybersecurity partners are ongoing.
Context
Cyber incidents within the education sector have become more frequent. According to recent government surveys, around a quarter of further education institutions (24%) reported experiencing a breach or attack at least weekly, and more than half of schools reported an attack or breach in the last year.
Practical Advice for Affected People
- Be alert for phishing attempts or unexpected contact: attackers may try to use leaked emails or phone numbers to impersonate official services.
- Do not share personal or financial details in response to unsolicited messages; verify any request by contacting official channels directly.
- Report suspicious messages and follow guidance from the DfE, ICO, or your organisation’s IT/security team.
The investigation is continuing with partner agencies to understand how the breach occurred and to reduce the risk of further incidents.
Help us improve.




























