Data security incident FAQs – Updated 280726 at 14:58
Latest updates will be shared on this page as and when further information is available.
1. What happened?
We recently identified unauthorised access to a digital service and immediately took steps to contain the incident and launch an investigation.
As a precaution, we have temporarily closed our Customer Help Portal and the Turing Scheme while we investigate. We apologise for the inconvenience and will provide updates to this document as more information becomes available.
2. When did the incident occur?
DfE were made aware of an attack on our Customer Help Portal and Turing portal on Monday 27 July. Once aware, we needed to establish the facts of the attack and investigate what had happened and why. After the initial investigation, we can confirm the information has been stolen.
3. What information may have been affected?
Investigations have found that the information involved include:
- Name
- Address
- Email address
- Telephone number
- Job title (Turing scheme only)
At this time, we do not believe that any further information has been shared. Once the investigation is complete, further updates will be provided.
4. What is DfE doing about this?
We have:
- Engaged with Microsoft and logged an incident to escalate the issue to their engineering team.
- Notified Information Commissioners Office (ICO)
- Temporarily closed the service while we carry out the investigation
- Increased monitoring across our systems
- Protecting customer information remains our highest priority and we will continue to provide updates on this page as and when further information is available.
Please refer to the Annex at the bottom of this article for further detail on the steps we have taken.
5. What should I be aware of and how can I protect my information?
There are ways you can help protect your information:
- Watch out for any suspicious emails, text messages and websites. There may be fake messages lurking amongst genuine ones that can be very difficult to spot. You can find further information on the National Cyber Security Centre’s (NCSC) website.
- Use strong passwords to protect your accounts. The ICO have a useful video.
- Inform your bank, building society and credit card company of any unusual transactions on your statement.
Annex A
Actions taken to date:
1. Activated formal cyber incident response arrangements immediately following notification from the NCA.
2. Established incident governance structures, including Gold Command oversight and a dedicated incident coordination team.
3. Prioritised forensic preservation, directing service teams not to undertake independent investigation or remediation activity.
4. Obtained and analysed the leaked datasets in a controlled environment before making any public assessment of authenticity.
5. Adopted a cautious communications approach, describing the incident as a potential cyber incident until sufficient validation had been completed.
6. Engaged national and industry partners, including the NCA, NCSC and Microsoft, to support investigation and validation activity.
7. Raised a Severity A incident with Microsoft to obtain specialist technical support.
8. Initiated a review of other Dynamics 365 and Power Pages services to determine whether the same exposure could exist elsewhere.
9. Commenced containment planning and remediation activity as confidence increased in the identified technical exposure.
10. Prepared for regulatory engagement, including ICO notification activity.
11. Escalated ministerial, senior leadership and communications arrangements as the likelihood of a genuine data exposure increased and media interest emerged.
12. Maintained investigation activity overnight and into 28 July to establish the full scope, impact and root cause of the incident.
Other ways to get help
Talk to our community
Discuss topics on further education and skills with other providers.
Is this page useful?