Hackers have stolen sensitive personal data from the UK Department for Education and a police database, exposing more than 740,000 pieces of information, including email addresses and phone numbers of parents, school staff, university employees, police officers and government officials.
The cyber-attack, which has been described as one of the largest breaches of public-sector data in recent years, is now under investigation by law enforcement and cybersecurity agencies. The stolen data includes full names, job titles, email addresses and telephone numbers of individuals connected to schools, universities and policing bodies across England and Wales.
Among those affected are senior school leaders, university staff, government officials, police officers and members of the public who had previously submitted their contact details to the Department for Education or related services. The data is believed to have been taken from internal databases and then published on the dark web, according to sources familiar with the incident.
The breach has raised serious concerns about the security of personal information held by public bodies. Parents and staff whose data was compromised have been urged to remain vigilant against potential phishing attacks, identity theft or fraudulent communications using the stolen details. Experts have warned that the combination of names, email addresses and phone numbers could be used to craft convincing scams targeting individuals in the education sector.
The Department for Education has confirmed that it is working with the National Cyber Security Centre and the Information Commissioner’s Office to investigate the attack and mitigate any further risks. A spokesperson said that affected individuals would be contacted directly and advised on steps to protect themselves, including changing passwords and monitoring accounts for suspicious activity.
The police database involved in the breach is understood to contain contact information of officers and staff, though no operational data or criminal intelligence is thought to have been compromised. Police forces have been alerted to the potential for targeted harassment or impersonation attempts using the leaked details.
Cybersecurity experts have called for a review of how public bodies store and protect personal data, noting that the scale of the breach points to vulnerabilities in the government’s digital infrastructure. The incident follows a series of high-profile attacks on UK public services, including previous data breaches at the NHS and local councils.
Opposition politicians have demanded a full parliamentary inquiry into the security of the Department for Education’s systems and the wider government approach to cybersecurity. They have accused ministers of failing to implement adequate protections despite repeated warnings from officials and independent auditors.
For those affected, the Information Commissioner’s Office has recommended reporting any suspicious emails or calls to Action Fraud, the UK’s national fraud reporting centre. The office has also reminded organisations of their legal duty to notify the regulator of serious breaches within 72 hours.
The attack underscores the growing threat posed by cybercriminals to public-sector institutions, which hold vast amounts of sensitive personal data on citizens. As investigations continue, authorities are working to determine the full extent of the breach and whether any of the stolen information has been used for criminal purposes.



