What is confirmed
The ministry says access obtained overnight on 25 July targeted a staff training system, potentially affecting employees who had worked in education authorities since 2001.
Potential fields include identity and job details and, for some people, address, phone and social security number. The system described held no bank details, passwords or student records.
What it means
On 18 August the ministry confirmed data had been published; a claim about student records remained under investigation and did not itself establish their inclusion in this extraction.
The July incident is separate from the March COMPAS and April EduConnect cases.
What to do
Follow direct notices from the ministry and education authorities; report suspicious emails through internal channels without clicking.
Verify any request for social security number, login credentials or payment supposedly from the ministry via a known contact.
Use the related SecurCheck tool, then confirm important decisions with an official source.


