Security Awareness for Schools: A Social Engineering Lesson

Office workers using computers in a modern workspace

The staff at the UK Department for Education did not hand attackers a password. They answered a help desk request, clicked a link, and responded to what looked like a legitimate internal process. On July 30, 2026, a threat group calling itself ExfilSquad confirmed they had used exactly that approach to steal 607,000 records from the DfE’s online customer help desk and the Turing Scheme portal. For Canadian school divisions, this is not a distant cautionary tale; it is a rehearsal for what is heading toward their own administrative staff.

How ExfilSquad got in through the help desk

According to reporting by IT Security Guru and Schools Week, the attack was a social engineering campaign targeting DfE staff and external contacts who used the help desk system. The stolen records include names, job titles, work email addresses, and telephone numbers belonging to school leaders, university staff, and government officials. ExfilSquad subsequently published the data online. The 607,000 figure refers to individual lines of data rather than the count of distinct individuals affected, and the DfE confirmed no financial information was accessed.

What makes this attack a useful study is the entry point. ExfilSquad did not exploit a zero-day vulnerability or purchase stolen credentials on a darknet forum. They targeted the trust that school staff place in internal service channels, the same trust that makes employees respond quickly and skip the verification steps they would otherwise apply to an external email. Understanding how employee behaviour becomes the primary attack surface is the starting point for any school that wants to address this class of risk. Help desk impersonation exploits the desire to be helpful, not the tendency to be careless, which is exactly why standard phishing email training does not prevent it.

Canadian schools are not watching from a safe distance

Canada’s education sector has already learned this lesson at significant cost. Mount Royal University in Calgary suffered a ransomware attack in June 2026 by the CMD Organization threat group, which demanded a $1.9 million ransom and claimed to have exfiltrated 10 terabytes of institutional data. Before that, the country’s largest school board and dozens of others received extortion demands tied to the December 2024 PowerSchool breach, with ransom notices arriving months after the incident, in May 2025, despite the company’s assurances that the stolen data had been deleted.

The training gap this attack exposes

The DfE breach illustrates a gap that conventional security awareness training does not always close: the difference between knowing not to click suspicious links in email and knowing how to handle an unexpected request arriving through a trusted internal channel. When the request comes through a help desk portal, a Teams message, or a call from someone who already knows your name and job title, the standard phishing-awareness instinct does not reliably activate.

Security awareness training reduces phishing click rates by 86 percent over twelve months, according to VikingCloud’s 2026 phishing statistics research. But that figure reflects improvement against email-based phishing, not against the social engineering calls and internal-channel impersonation that ExfilSquad used. Programs that measure click rates on simulated phishing emails are measuring a narrower slice of employee readiness than the current threat demands.

What school administrators can do this week

The practical response is not to overhaul a program overnight. Run one targeted scenario this week: have someone contact administrative staff through an internal channel (help desk system, chat, or a direct call) pretending to be from IT, and measure how many respond without independently verifying the caller’s identity. The result reveals your school’s actual risk posture. When you are ready to address the full picture, starting with a cybersecurity posture assessment gives you a baseline grounded in what your staff actually do, not what your training policy says they should do.

In our work with Canadian school divisions, we consistently see IT teams stretched thin and security awareness training competing with twenty other priorities. When threat actors like ExfilSquad target this sector through social engineering, it is not because school staff are negligent, it is because they are under-resourced relative to the threat and rarely receive the targeted training they need to recognize an attack that does not look like a spam email.

Sources