Politics

Teachers’ names and phone numbers leaked on dark web after Department for Education hacked

Teachers’ names and phone numbers leaked on dark web after Department for Education hacked

The names and phone numbers of thousands of school leaders, university staff and government officials have been leaked onto the dark web after the Department for Education (DfE) was hacked.

Online thieves reportedly stole 607,000 records in the attack, including full names, job titles and email addresses of people who have engaged with the department.

According to The Times, which first reported the breach, the hackers targeted the DfE help desk, which manages requests from local authorities and school leaders, as well as records from the Turing Scheme – the database education institutes use to oversee UK students who study overseas.

However, DfE sources told The Independent the data protection risk to those affected is not considered high, noting that data obtained includes different sets of data which cannot be connected.

They are understood to have reported the incident to the Information Commissioner’s Office, and is working with the National Crime Agency (NCA) and National Cyber Security Centre (NCSC).

The department is understood to be fixing the help desk portal and the Turing scheme portal following the hack, and has switched telephone communication while maintenance work is done.

Dark web posts seen by The Times reportedly shows a cybercriminal group called ExfilSquad claiming responsibility for the breach.

Jake Moore, an adviser at leading European cybersecurity firm ESET, warned that government agencies are “soft targets” for cybercriminals, arguing that this attack “isn’t a one off”.

He said: “Government agencies often lack proper funding and consequently may not have the best protection for their systems, making them soft targets for cybercriminals. With weaker security, government agencies and departments can also get unintentionally caught up in a net of ransomware attacks when other companies are targeted.

“The issue is this isn’t a one off and the UK government should be learning from its mistakes. There are now multiple examples of government and local government agencies being struck in similar attacks which often lead to weeks of disruption and have a huge knock-on effect to wider communities.

“When information like this is stolen, criminals can still do a lot by piecing together a data jigsaw and even creating convincing follow up phishing emails to lure people into clicking into malicious sites. It’s best to remain vigilant to any unsolicited communication.”

A Department for Education spokesperson said: "We have robust processes in place to protect information and took swift action to contain this incident. The information involved is limited to customer service contact details relating to individuals and organisations. No other data has been accessed.

"We continue to work closely with the National Cyber Security Centre and the National Crime Agency.”

You may have missed