Department for Education
We read the privacy notices published across central government, councils, tax and benefits offices, health bodies and policing. These are the patterns that repeat. A public body is not a company and you are not its customer: it holds your record because a law lets it, which changes what you can ask for and what you can expect back.
Reported incidents
607,000 contact records taken from its help desk and Turing Scheme portals
2026-07-29Affected Help desk self-service portal and Turing Scheme portal
The Department for Education in England confirmed in late July 2026 that attackers had taken about 607,000 records from its help desk self-service portal and the Turing Scheme portal, which handles funding for study abroad. The records hold names, job titles, phone numbers and email addresses of head teachers, school leaders, university staff and government officials. The department said bank details and other sensitive data were not included. A group calling itself ExfilSquad claimed the attack and posted the data. The department reported itself to the ICO and is working with the National Cyber Security Centre and the National Crime Agency.
People affected typically ask Department for Education to confirm whether their information was included, and which categories.
The verified route
DÆTRAX is a personal data accountability ledger: a dated record of which companies hold your personal data, what you asked them to do about it, and what they claimed in reply.