Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Yes. Student-data breaches and other cyber incidents are common across UK education, with the highest reported prevalence in further- and higher-education institutions. A cyber attack is not automatically a personal-data breach: the legal issue is whether personal information was exposed, changed, destroyed or made unavailable in a way that risks harm to people.

How common are data breaches in UK schools and universities?

The 2025/2026 Cyber Security Breaches Survey, conducted by DSIT and the Home Office, covered 273 primary schools, 222 secondary schools, 33 further-education (FE) colleges and 49 higher-education (HE) institutions. Fieldwork took place from August to December 2025. It measured organisations that had identified a breach or attack during the previous 12 months; attacks that went undetected are not included, so the true prevalence may be higher.

Education setting Institutions surveyed Identified a breach or attack in the previous 12 months Reported incidents at least weekly
Primary schools 273 49% 14%
Secondary schools 222 73% 20%
Further-education colleges 33 88% 24%
Higher-education institutions 49 98% 29%

Among institutions that identified an incident, phishing was reported by 90% of primary schools, 96% of secondary schools, 96% of FE colleges and 96% of HE institutions. In FE and HE combined, the same survey recorded impersonation at 79%, malware at 51% and denial-of-service attacks at 49%.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Those figures describe detected “breaches or attacks”, not a count of legally reportable personal-data breaches. A school can block an attempted attack before any personal information is exposed, while a wrongly emailed spreadsheet can be a personal-data breach without being a sophisticated cyber attack.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Cyber attack versus personal-data breach

A cyber attack is an attempt to compromise systems, accounts or services. Examples include phishing, malware, ransomware, denial-of-service activity and attempts to guess or steal passwords.

A personal-data breach is a security failure affecting the confidentiality, integrity or availability of personal information. It can involve:

  • Someone viewing student records without authorisation.
  • Records being altered or deleted.
  • Ransomware or another failure making records unavailable.
  • Stolen credentials being used to enter an account or system.
  • A staff member sending a file to the wrong person or to a personal device.
  • A lost, stolen or inadequately protected device exposing stored information.

The distinction matters because the DSIT/Home Office survey reports identified attacks and breaches, whereas the Information Commissioner’s Office (ICO) reporting duty applies when a personal-data breach is likely to create a risk to individuals’ rights and freedoms.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

What data do schools, colleges and universities hold?

The exact dataset varies by institution, age group and course, but education systems commonly contain combinations of:

  • Names, addresses, dates of birth and contact details.
  • School, college or university records, attendance and assessment information.
  • Health information, disability or learning-support details.
  • Safeguarding, pastoral and welfare notes.
  • Emergency contacts and information about parents, carers or dependants.
  • Admissions, applicant, staff and placement records in further and higher education.
  • Account credentials, device identifiers and logs showing use of online services.

The sensitivity and volume increase the potential consequences of a breach. In one ICO case, a student used a staff login to view, amend or delete information about more than 9,000 staff, students and applicants, including names, addresses, school records, health data, safeguarding and pastoral logs, and emergency contacts.

How phishing and insider access combine

Phishing is often the entry point rather than the final event. An attacker may send a convincing message that captures a staff member’s or student’s password, then use that account to access cloud storage, email, learning platforms or administration systems. If the account has excessive permissions, the incident can look like an insider breach because a valid login is being used to view or change records.

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Impersonation can work the same way without a stolen password: a criminal poses as a colleague, supplier or senior manager and persuades someone to disclose information or approve an action. Malware and ransomware can then spread through the compromised account or device, while a denial-of-service attack can interrupt services even when records are not disclosed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In FE and HE institutions that identified an incident, 49% reported a negative systems outcome. The reported effects included compromised accounts or systems being used illicitly (23%), slowed or unavailable web services (16%) and loss of access to files or networks (14%).

Can students cause data breaches?

Yes. The ICO analysed 215 education-sector personal-data breach reports caused by insiders between January 2022 and August 2024. Students were responsible for 57% of those incidents. Stolen login details appeared in 30% of incidents, and students were responsible for 97% of the stolen-login cases.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Insider incident pattern in the ICO analysis Share of 215 incidents
Students caused the incident 57%
Stolen login details involved 30%
Poor data-protection practices 23%
Staff sent data to personal devices 20%
Incorrect access-rights setup 17%
Sophisticated bypass techniques 5%

The categories can overlap, so they should not be added together as if they were mutually exclusive. “Insider” does not necessarily mean a malicious employee or student; it can include accidental disclosure, weak permissions, a shared password or misuse of a legitimate account.

The ICO described a case in which three Year 11 students accessed a secondary-school information system containing personal information on more than 1,400 students. In another, a student used a staff login to access, alter or delete records relating to more than 9,000 people. These examples show why shared credentials, unreviewed permissions and unrestricted access create risk even when the original compromise begins with a student account.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What controls reduce the risk?

The Department for Education’s Cyber Security Hub advises education settings to ensure that everyone can recognise phishing and ransomware, use strong passwords, follow security policies, use approved software and services, and report concerns promptly. Its figures indicate that fewer than 40% of schools have a cyber-incident response plan and fewer than one quarter use multi-factor authentication (MFA) on supported cloud services.

Best Value
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-A Type TrustKey T110
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.

The latest survey found that at least seven in ten institutions had a formal cyber-risk or cyber-continuity policy, but no education tier had a majority covering all 10 National Cyber Security Centre (NCSC) Steps to Cyber Security. Coverage was 14% in primary schools, 23% in secondary schools, 33% in FE and 45% in HE. Nearly half of HE institutions (49%) and 27% of FE colleges said employee or student personal data was stored without protections such as anonymisation or encryption.

Account and access controls

  • Require MFA wherever the service supports it, prioritising staff, administrators and remote access.
  • Use unique passwords and eliminate shared credentials.
  • Apply least-privilege permissions, especially to safeguarding, health and administrative records.
  • Review joiner, mover and leaver access promptly when people join, change role or leave.
  • Monitor privileged-account activity and investigate unusual downloads, logins or data changes.

Device, software and data controls

  • Lock screens and prevent unsupervised use of staff devices.
  • Restrict downloads, personal email and unapproved cloud services.
  • Patch operating systems, applications and network equipment.
  • Encrypt or anonymise personal data where appropriate and minimise retention.
  • Map what student information is held, where it is stored and who can access it.

People and response planning

  • Train staff and students to identify phishing, impersonation and suspicious access.
  • Make reporting simple and non-punitive so a suspected mistake is raised quickly.
  • Maintain tested incident-response and business-continuity plans, including out-of-hours contacts.
  • Practise restoring systems and communicating with students, families, staff and regulators.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What should you do if a school or university says your data was breached?

  1. Verify the notification. Contact the institution through its published website or a known telephone number rather than using links or phone numbers in an unexpected message.
  2. Find out what happened. Ask which systems were affected, the incident dates, what categories of data were involved, whether your records were actually accessed, and what the institution has done to contain the problem.
  3. Change reused passwords. Start with the affected account, then change the same password anywhere else it was used. Use a unique password for each service.
  4. Turn on MFA. Enable it on the affected education account and on personal email or other accounts that could be used to reset it.
  5. Expect follow-up scams. Treat later requests for passwords, payment, identity documents or urgent action as suspicious, even if the sender knows details about the incident.
  6. Protect financial or identity information. If the notification says payment, identity or bank information was exposed, contact the relevant provider through its official channel and monitor statements and account activity.
  7. Keep records. Save the notification, dates, questions and responses. This helps if the institution changes its advice or you need to explain resulting fraud or harm.
  8. Use the institution’s data-protection contact. Ask for its data-protection officer or incident contact if the notification does not explain the risk or the protective steps available to you.

How quickly must a UK school report a data breach?

Under current ICO guidance, an organisation must report a notifiable personal-data breach to the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it. The 72-hour period is not a deadline for every cyber incident: the breach must meet the threshold for notification because it is likely to create a risk to people’s rights and freedoms.

An ICO notification should describe the nature of the breach, the categories and approximate numbers of people and records affected, the likely consequences, and the measures taken or proposed to mitigate harm. If the breach is likely to create a high risk to individuals, the affected people must also be told without undue delay, using clear information about the risk and what they can do.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The ICO’s guidance page was under review after the Data (Use and Access) Act came into force on 19 June 2025. Institutions should therefore use the current ICO guidance and their data-protection officer’s advice rather than relying on an old policy or treating the wording as permanent legal advice.

What students and staff can do every day

  • Never approve an unexpected MFA prompt or disclose a password in response to a message.
  • Check the sender address and destination of links before signing in.
  • Report suspected phishing immediately, even if no information was entered.
  • Do not download student records to a personal device or transfer them to an unapproved service.
  • Lock the screen whenever leaving a device and keep devices physically secure.
  • Use only the access needed for the task and challenge permissions that seem excessive.
  • Report a lost device, misdirected email or accidental disclosure as soon as it is noticed.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.