School leaders are seeking assurances after sensitive data was stolen from the Department for Education.
The security breach, believed to have occurred last week and first reported by The Times, comes a year after Vlog reported a separate data leak: the DfE reported five personal‑data breaches to the Information Commissioner’s Office (ICO), incidents that “potentially affected” more than 84,500 people.
Now it is being reported that more than 600,000 data points, including names and email addresses of senior leaders in schools, have been stolen.
Vlog asked the DfE how many individuals may have been affected this time, but it did not provide a response on this detail.
DfE defends response to data leak
The DfE maintains that the data protection risk to individuals “is not considered high” and has referred itself to the ICO.
A spokesperson said: “We have robust processes in place to protect information, and took swift action to contain this incident.
“The information involved is limited to customer service contact details relating to individuals and organisations. No other data has been accessed.
“We continue to work closely with the National Cyber Security Centre and the National Crime Agency.”
Munira Wilson, the Liberal Democrats’ spokesperson for education, children and families, told Vlog: “This is the second horrifying DfE data breach in less than three years.
“The department must urgently tell affected parents and students exactly what data has been compromised, who is at risk and what steps they should take to protect themselves.”
‘Failure to learn lessons’
Ms Wilson, who had described the previous breach as “deeply worrying”, called on the DfE to explain why “it has failed to learn the lessons needed” to prevent personal data from being at risk.
The datasets impacted by the breach are the DfE helpdesk self-service portal and the Turing Scheme portal, which is used to manage funding for international placements.
Both portals include important contact details. The DfE says the issues with both are being resolved as a matter of urgency. It has switched to phone communications in the meantime.
Pepe Di’Iasio, general secretary of the Association of School and College Leaders, said: “We’re very concerned that personal data, including that of school leaders, has been leaked in this way. It’s obviously not the first time that something like this has happened, and it does appear that cyberattacks are becoming both more frequent and increasingly sophisticated.
“As well as being fully transparent about what has happened in this latest attack, the government needs to look at strengthening its cybersecurity to ensure sensitive information can be kept safe.”
Paul Whiteman, general secretary of the NAHT school leaders’ union, said: “These reports are concerning. While school leaders’ names and email addresses will largely be in the public domain anyway, the DfE needs to act quickly to reassure people by clarifying exactly what information has been accessed and that it goes no further.
“Cyber leaks can have serious consequences and so it will be incumbent on the department to get to the bottom of what has happened and reassure the sector that steps have been taken to prevent any recurrence.”
Guidance for individuals affected by a data breach can be accessed through the .