Skip to main content

The DfE breach and what it means for identity security in the education sector

On July 29, 2026, the Department for Education (DfE) for the United Kingdom confirmed that more than 600,000 lines of contact data had been taken from its customer help desk portal, alongside a smaller dataset from the Turing Scheme service.

For every school, college and trust, that leaves one practical question:

Who can reach your everyday systems, how much can they access, and would unusual identity activity be spotted quickly?

Students in a classroom using computers
Department for Education building

The DfE cyberattack in brief

  • 600,000+ lines of contact data taken: Names, work email addresses, telephone numbers and job titles of school leaders, local authority staff, parents and university contacts.
  • Two education services affected: The customer help desk portal, plus the Turing Scheme service used to manage international study and work placements.No financial or safeguarding records, and no ransomware, have been publicly identified. However, names, roles and contact details are exactly what make later phishing and impersonation attempts more convincing.
  • Social engineering attack followed by demands: A group calling itself ExfilSquad published samples and demanded payment to prevent the remaining data from being released. Reports link the entry point to social engineering of an external-facing help desk.

Why this matters to schools and trusts

  • Education organizations depend on Active Directory, Microsoft 365, finance and HR platforms, staff and parent portals, learning applications and externally managed support services. Access to all of them changes continually.
  • Staff join and leave. Teachers move between schools. Contractors and supply staff receive temporary access. Central IT delegates work to local technicians and third-party providers.
  • Without a consistent identity management process, permissions gradually drift away from what was originally approved.
  • A compromised identity with narrow, current permissions has limited reach. The same identity with outdated or excessive access can affect several systems, schools or datasets.
UK school campus

Why review identity controls now

Renewed focus on cybersecurity

The breach has put education security back under scrutiny, just as schools and colleges are being asked to improve their digital and cyber controls ahead of the DfE's 2030 digital and technology standards.

Some identity requirements are already due

The DfE states that schools and colleges should already be controlling user accounts and access privileges. Where controls are missing, a structured rollout is expected to begin as soon as possible.

Reduce immediate identity risk

Review privileged accounts, remove unnecessary permissions, and ensure only the right people can access sensitive systems and data.

Show measurable progress towards 2030

Build evidence that identity and access controls are being implemented, monitored and improved in line with the DfE's 2030 digital and technology standards.

How AD360 supports identity security in education

  • Keep access aligned with the staff life cycle

    Provisioning, role changes and deprovisioning across Active Directory and Microsoft 365. Role-based delegation lets school-level technicians complete selected tasks without broad native privileges, while approval workflows add oversight to sensitive changes.

    • Consistent onboarding and offboarding
    • Fewer dormant accounts
    • Safer central-to-local delegation
    • Evidence for termly access reviews

Five questions for your next identity review

Is MFA applied everywhere the DfE standard requires it?

Question 1 of 5

Include staff cloud access, remote access and all IT administrative accounts.

Review your school or trust’s identity controls

Assess how your current Active Directory and Microsoft 365 environment supports the controls expected by the DfE standards.