Department of Education confirms cyberattack

More than 600,000 records were stolen in the latest incident, following similar breaches at the Legal Aid Agency, Electoral Commission and British Library

Department of Education confirms cyberattack

Cyber

By Josh Recamara

The Department for Education (DfE) has confirmed that the names and contact details of thousands of school leaders, university staff and government officials were exposed in a cyberattack, an incident that adds to a growing list of UK public sector breaches and highlights a persistent gap in the country's cyber insurance market.

Thousands of records stolen

According to The Times, which first reported the incident, hackers stole around 607,000 records, including full names, job titles and email addresses, after targeting the DfE help desk and the database used to administer the Turing Scheme, which oversees UK students studying overseas. A group calling itself ExfilSquad has claimed responsibility on the dark web.

DfE sources told The Independent that the risk to those affected is not considered high, as the stolen data consists of separate sets that cannot be linked together. The department has reported the breach to the Information Commissioner's Office (ICO) and is working with the National Crime Agency and the National Cyber Security Centre.

"We have robust processes in place to protect information and took swift action to contain this incident," a DfE spokesperson said. "The information involved is limited to customer service contact details relating to individuals and organisations. No other data has been accessed."

Jake Moore, an adviser at cybersecurity firm ESET, said public bodies are frequent targets because of resourcing gaps. Government agencies "often lack proper funding and consequently may not have the best protection for their systems, making them soft targets for cybercriminals," he said, warning that the incident is unlikely to be an isolated one.

Why government departments sit outside the commercial cyber market

For insurers and brokers, the more instructive point is what does not happen after a breach like this. Central government departments and their agencies typically do not carry commercial cyber insurance in the way large private-sector organisations do. Instead, they rely on internal risk management and, where relevant, government indemnity arrangements, effectively self-insuring against incidents of this kind.

That has been borne out repeatedly. The Legal Aid Agency, an executive agency of the Ministry of Justice, disclosed in May 2025 that attackers had accessed a substantial volume of personal data belonging to legal aid applicants dating back to 2010, including national insurance numbers and financial details. The Electoral Commission previously exposed the data of around 40 million voters and received only a reprimand from the ICO rather than a fine. The British Library and Greater Manchester Police have suffered similar high-profile intrusions in recent years. In each case, the losses were absorbed within government rather than settled through a commercial policy.

This leaves the insurance market's exposure to public sector cyber risk concentrated further down the supply chain, among the IT services providers, managed service firms and contractors that support government systems and that do buy commercial cover. A department-level breach can still generate claims activity if it implicates a third-party supplier's systems or controls, even where the department itself carries no policy.

A market still expanding around that gap

The incident lands as the UK cyber insurance market continues to grow quickly. The UK's broader cyber security sector reached £13.2 billion in revenue in 2025, up 12% year on year, according to Gallagher's UK Cyber Market Report 2026, with insurers widening coverage and easing entry conditions for businesses that can demonstrate strong controls. The UK cyber insurance segment specifically was valued at approximately $2.00 billion in 2026, according to Market Data Forecast, which projects growth at a compound annual rate of 14.21% through 2034, driven by rising ransomware incidents, expanding regulatory requirements and growing digital transformation across industries.

Regulation is tightening in parallel. The Cyber Security and Resilience Bill reached report stage in the House of Commons in May 2026 and is progressing to the Lords, with Royal Assent expected later this year. It will extend the UK's NIS regime to data centres, managed service providers and critical suppliers, and confirms a targeted ban on ransomware payments by public sector bodies and regulated critical national infrastructure operators, alongside tighter mandatory incident reporting requirements. That expanded scope is likely to draw more of the public sector supply chain into mandatory reporting and, in turn, into conversations with brokers about cover.

Most significant cyber threat

The National Cyber Security Centre has identified ransomware as the most significant cyber threat facing UK organisations, and separate market analysis from Mordor Intelligence noted that ransomware continues to account for the dominant share of UK cyber insurance payouts relative to notifications.

With that threat persisting and regulatory scrutiny increasing, breaches such as the DfE's are likely to keep reinforcing demand for cyber cover and incident response capability among suppliers and contractors that surround government, even as departments themselves remain largely self-insured and outside the commercial market insurers are competing to grow.

Related Stories

Keep up with the latest news and events

Join our mailing list, it’s free!