Schools

30k primary pupils’ data may be at risk after Capita cyber attack

Dark web monitored for the information after company was targeted in March

Dark web monitored for the information after company was targeted in March

Exclusive

Tens of thousands of primary pupils’ details may have been stolen in a huge cyber-attack at government outsourcer Capita, Schools Week can reveal.

The dark web is being monitored for the information after the company was targeted in March, with 90 organisations reporting breaches of personal data held by Capita.

Capita runs several services for the Department for Education, including administering primary school SATs for the Standards and Testing Agency (STA).

Documents obtained by Schools Week reveal up to 30,000 pupil personal data records under the STA contract are “believed to have been exfiltrated”.

In its report to the Information Commissioner’s Office (ICO), the DfE said this included “pupil names, dates of birth, pupil IDs, test types and school reference numbers, in additional (sic) to other non-identifiable management data”.

It did not contain “any addresses for the pupils or contact details or names of schools, exam results; or any special category personal data or any financial information.

“Whilst name and date of birth are unlikely to present a high risk, should the information be made public for sale, it is likely to cause distress.

“The added inclusion of a school identifier may increase the likelihood of identification, but is unlikely to present a greater risk to the data subjects, unless there is a safeguarding issue potentially.”

However, in May the DfE said because there “is not a high risk posed, we are currently unlikely to inform the STA data subjects”.

Capita estimated the attack could cost up to £20 million.

‘Potentially compromised forever’

When asked about the SATs data breach, a spokesperson said it had “found no evidence of any information in circulation, on the dark web or otherwise, resulting from the cyber incident”.

Jen Persson, the director of the campaign group DefendDigitalMe, said children’s names and dates of birth was “critical identity data. These children and related family members are potentially compromised forever.

“If it’s not (yet) been put up for sale, it also begs the question who or what organisation might want children’s identities for what reasons.”

It was initially thought that several thousand teacher pension scheme members could also have been impacted.

But the DfE’s submission said in May only one member “most likely” had personal information taken.

It said Capita was monitoring the teacher’s account for “suspicious activity” and providing them with a 12-month membership of Experian Identity Plus, which alerts members to potential suspicious activity.

In the ICO report, the DfE said breached data figures have “changed several times (both up and down) and is not confirmed”. Neither the DfE nor Capita confirmed if the figure had changed as of this week, nor whether it had been communicated to pupils or their families.

The DfE said that almost all STA data was stored on uncompromised servers. A spokesperson said it was in “regular contact” with Capita as “it continues investigations”.

Data was taken from less than 0.1 per cent of Capita’s server estate, the company said in May.

“Having taken extensive steps to recover and secure our data … we still have found no evidence of any information in circulation, on the dark web or otherwise, resulting from the cyber incident,” it said in a statement this week.

An ICO spokesperson said it was “making enquiries” into the incident.

Latest education roles from

IT Technician

IT Technician

Harris Academy Morden

Teacher of Geography

Teacher of Geography

Harris Academy Orpington

Lecturer/Assessor in Electrical

Lecturer/Assessor in Electrical

South Gloucestershire and Stroud College

Director of Management Information Systems (MIS)

Director of Management Information Systems (MIS)

South Gloucestershire and Stroud College

Exams Assistant

Exams Assistant

Richmond and Hillcroft Adult & Community College

Lecturer Electrical Installation

Lecturer Electrical Installation

Solihull College and University Centre

Sponsored posts

Sponsored post

Turbo boost your pupil outcomes with Teach First

Finding new teaching talent for your school can be time consuming and costly. Especially when you want to be...

SWAdvertorial
Sponsored post

Inspiring Leadership Conference 2025: Invaluable Insights, Professional Learning Opportunities & A Supportive Community

This June, the Inspiring Leadership Conference enters its eleventh year and to mark the occasion the conference not only...

SWAdvertorial
Sponsored post

Catch Up® Literacy and Catch Up® Numeracy are evidence-based interventions which are highly adaptable to meet the specific needs of SEND / ALN learners

Catch Up® is a not-for-profit charity working to address literacy and numeracy difficulties that contribute to underachievement. They offer...

SWAdvertorial
Sponsored post

It’s Education’s Time to Shine: Celebrate your Education Community in 2025!

The deadline is approaching to nominate a colleague, team, whole school or college for the 2025 Pearson National Teaching...

SWAdvertorial

More from this theme

Schools

Drop in teacher job adverts as falling rolls and cuts bite

Headteachers say they are expecting to employ fewer staff amid falling pupil numbers and financial pressures

Lydia Chantler-Hicks
Schools

Surge in school cuts ‘threatening Labour’s opportunity mission’

Poll for Sutton Trust charity finds rise in leaders laying off staff and cutting curriculum as funding storm hits...

Rhi Storer
Schools

Parents to get more of their money back from sQuid

Company said it had 'reviewed its refund policy' after Schools Week revealed parents' concerns

Freddie Whittaker
Schools

DfE bans former head of ‘holistic’ AP school after Ofsted safety concerns

Ofsted inspectors found pupils at the Devon school could access nearby train tracks and industrial units

Lydia Chantler-Hicks

Your thoughts

Leave a Reply

Your email address will not be published. Required fields are marked *