What is confirmed
The ministry describes impersonation of an authorised staff account in late 2025 and exploitation of a since-patched flaw in a service linked to EduConnect.
First name, surname, login ID, school and class were listed, alongside email when supplied and an activation code for some accounts not yet activated.
What it means
The ministry says EduConnect accounts already activated at the time were not compromised by this incident.
For inactive accounts, activation codes were reset and undistributed accounts blocked; the precise number of affected students was still being assessed.
What to do
Parents and students: consult school notices through familiar channels and access EduConnect via its official address.
Report messages requesting activation codes, documents or payment to the school.
Use the related SecurCheck tool, then confirm important decisions with an official source.


