What is confirmed
An intrusion on 15 March into COMPAS, a trainee management system, followed the impersonation of an external account according to the ministry.
Initial findings cited about 243,000 staff, trainees or permanent employees and identity details, contact information, absence periods without health details, and some tutor information.
What it means
This is the March COMPAS incident; its figure should not be attributed to the separate April or July incidents.
Exposed contact details can increase the risk of targeted fake administrative messages.
What to do
Affected staff should follow official notices from the ministry and their education authority.
Independently verify any emailed request for documents, passwords or account changes.
Use the related SecurCheck tool, then confirm important decisions with an official source.


