Jump to content

Recommended Posts

Posted

Dear Client

We are writing to inform you, as the data controller, of a potential data breach that has occurred involving data processed by Single Central Record Ltd, acting as the data processor. We are committed to maintaining the highest standards of data protection and transparency, and it is in this spirit that we provide you with the following details.

Description of the Incident

On 17th August 2025 we were notified by Intradev, our external software supplier, that a part of their system had been subject to unauthorised access. The incident itself occurred around 31st July 2025. Intradev confirm that certain files that relate to personal data were copied from their systems. Our own network and servers were not compromised. We are actively investigating why Intradev had copies of some of our data in their systems.

Nature of the Data

The data potentially affected by this breach includes personal identification information. At this stage, we are conducting a thorough analysis to determine the full scope of the data involved. From our assessment so far, the scope of the data appears to be limited to an audit table used to record certain changes or actions made in the Single Central Record.

Potential Impact

The potential impact on the data subjects may include identity theft. We are actively assessing the situation to understand the extent of the impact and will keep you informed of any significant developments.

Immediate Actions Taken

Upon discovery of the breach, we immediately obtained a report from Intradev detailing the nature of wthe breach. We have undertaken a review of our own systems, which have not been affected. Although we are not the data controller, we have been pragmatic and made a report to the Information Commissioner's Office (ICO).

Next Steps

We recommend that you, as the data controller, consider reporting the matter to the ICO and to notify potentially affected data subjects. You can report the matter to the ICO on their website https://ico.org.uk/for-organisations/report-a-breach and contact them for advice on 0303 123 1113. We will do our best to assist you to address this situation and mitigate any potential harm to the data subjects.

Should you require more detailed information to fulfill your own data controller obligations, please contact us. We are prepared to assist you in assessing the full nature of the data upon your request.

Contact Information

For further communication regarding this matter, please contact us on [email protected] or 0151 606 5101. We are available to discuss any concerns you may have and to provide additional information as it becomes available.

We take this matter very seriously and are committed to resolving it promptly and effectively. Thank you for your attention to this urgent issue.

Sincerely,

SCR Team

Posted

I have a data breach resource kit for this incident if anyone thinks it would be useful. The kit is free and includes risk grids, letter template, governor briefing and school comms.

 

It is in draft form, does not constitute legal advice and it is recommended that all actions are confirmed with your school DPO prior to use.

 

Hope it helps a little.

_OnlineSCR data breach pack.zip

Posted

More concerning is that the breach happened in July, but schools were only notified at the end of August.

My school wants to switch supplier in light of this.   Who do other schools use for this kind of thing?

Posted

I'm told a lot of folk prefer a google sheet or something roughly equivalent! Is that true? There's a degree to which building a company around something this niche is asking for data breach issues

Posted

Just got this from Exclaimer wonder if its the same thing

 

Incident Summary

 

We recently identified unauthorized data access through Drift, an AI-powered chatbot owned by Salesloft, which had been connected to our Salesforce and Zendesk platforms. Once we became aware of the issue, we immediately disabled all Drift integrations.

 

Our investigation, conducted in coordination with Zendesk and Salesloft, confirmed that certain Zendesk and Salesforce data was accessed. To be clear, Exclaimer’s own systems were not breached. The accessed data included business email addresses associated with your organization, including this address.

Posted

Does anyone have a real handle on the scope and scale of this incident?  The back-end provider seems to have been used by several services, across several sectors. It feels to me like it could be somewhere between everyone with a dbs check, or only a few thousand people. Anyone found they are on the list? (though maybe we don't want to say, just in case cross referencing the users from here against the list provides further advantage to the bad-guys)

Posted

We use a different system, but our DPO service sent this mailshot this afternoon

 

Quote

What happened? 

On 17th August 2025, the Online SCR was notified by its software supplier, Intradev Ltd, about a cyber-attack that resulted in unauthorised access and copying of personal data records processed on behalf of education settings. The breach was traced to the supplier’s internal infrastructure, which Online SCR uses to help deliver its services.  

It is important to be aware that the internal systems operated by Online SCR were not directly compromised by this incident and they have informed their customers that services can continue as normal.  

The Online SCR has duly reported this personal data breach to Information Commissioner’s Office  (‘ICO’) and taken a proactive approach to notify their affected customer base.  

Further updates about the incident are to be provided to their affected customers as their investigation progresses. 

What happened?

On 17th August 2025, the Online SCR was notified by its software supplier, Intradev Ltd, about a cyber-attack that resulted in unauthorised access and copying of personal data records processed on behalf of education settings. The breach was traced to the supplier’s internal infrastructure, which Online SCR uses to help deliver its services.  

It is important to be aware that the internal systems operated by Online SCR were not directly compromised by this incident and they have informed their customers that services can continue as normal.  

The Online SCR has duly reported this personal data breach to Information Commissioner’s Office  (‘ICO’) and taken a proactive approach to notify their affected customer base.  

Further updates about the incident are to be provided to their affected customers as their investigation progresses. 

Who is affected by the breach?

If your school and/or Trust uses Online SCR, you may have been impacted by the breach.  

During the summer school holidays, you should have been contacted by Online SCR and received an email update from them detailing what has happened with confirmation as to how the breach has affected you and your staff. However, due to school holidays and staff being on leave, some communications may not yet have been received. We also encourage you to check your junk folder for any correspondence you may have received. 

In each communication, you should have received an Excel Spreadsheet from the Online SCR that contains a tailored breakdown of what personal information was compromised; how many people have been affected; and what types of information are at risk.  

If you have not been contacted by Online SCR to date, or no longer use this service provider, then you may not have been affected by the breach. However, we recommend considering getting in touch with the Online SCR to help confirm this point.  

For any questions about the breach, or to confirm if you have been affected, the Online SCR has recommended you get in touch with them by emailing: [email protected]   

What information is at risk?

We are currently awaiting more details from Online SCR. However, we understand that the breach may have affected some or all the following information: 

    Name 

    Phone number 

    Date of birth 

    Email address 

    Postal address 

    Place of birth 

    National Insurance number 

    Passport number 

    Driving licence number 

    QTS numbers (teaching qualification) 

The affected information does NOT include: 

    Financial details 

    Passwords 

    Medical information 

    Information on any disclosures (e.g. criminal records) 

    Information about protected characteristics (e.g., ethnicity, disability, sexual orientation, marital status) 

The personal data that was accessed was in text format only. No original documents or images were affected. 

Recommended Next Steps

If your School or Trust use Online SCR, or have been a customer with this provider in the past, we recommend you consider taking the following steps: 

    Confirm Risk Impact: Contact the Online SCR to verify whether your organisation’s data has been affected by this breach. You should also check if you have received any emails from this provider – as some of these notifications can end up in your spam/junk folders.  

    Notify the ICO: As the data controller, your school or trust must report the breach to the ICO within 72 hours of becoming aware of it.

        Should you need to report this breach to the regulator, you can include the SCR’s breach reference in your report - IC-415209-Y2T2

        However, it is important to stress you may not need to do this in every case. We recommend you contact our team or your local DPO first to verify if any individuals are at higher risk because of the breach. Not all affected individuals are necessarily in this group – so best to check before reporting.   

    Inform Data Subjects: Notify affected individuals at a higher risk of harm with clear and supportive guidance. You can use and adapt the Data Breach Notification Template Word document supplied by the Online SCR to help notify affected individuals about the following:

        Explain what information is at risk because of the breach; and

        Practical steps on how to mitigate higher risks of scams (e.g., phishing attempts); and 

        Provide contact details for support from third party organisations (such as Action Fraud or Credit Agencies).

        If you do not have a copy of this Data Breach Notification Template, or you prefer to tailor the wording before contacting any affected staff, please get in touch with us so we can provide you with further support. Review Contracts: you should review your Service Agreement with the Online SCR to consider any necessary legal or financial recourse. XXX can support with the review of any terms governing data protection. However, you may wish to seek independent legal advice for other contractual terms you feel are unclear. 

    Update DPIAs: If you have not done so already, schools and Trusts using Online SCR should carry out or update their Data Protection Impact Assessment (‘DPIA’) for use of this service to document this new risk. 

    Assess Liability: some of your staff, who must be made aware of the breach, may warn you or decide to issue a claim for compensation against their employer. This can be a typical reaction after receiving such news in many cases. We recommend education settings prepare themselves for this possible risk. 

 

  • 6 months later...
Posted
Quote

Fraudulent letter – DfE “National Regulatory Notice”

We are sorry to contact you over the holiday period, but we thought you should be aware that some academy trusts have received a letter presented as a DfE “National Regulatory Notice”. It includes a ministerial signature and claims there has been a data breach involving Online SCR / Intradev.

This letter has been confirmed by the DfE as fraudulent and has not been issued by the minister’s office.

All trusts must not: 

  • follow any instructions in the letter
  • share data or comply with the directions

All trusts must:

  • ensure senior leaders, governance leads and administrative teams are aware
  • report any receipt of the letter to your usual DfE contact or contact the DfE through GOV.UK

If anyone has already acted on the letter, notify your trust’s IT or security lead. You should also report it through your usual process and monitor systems for unusual activity. Follow the Academy trust handbook for guidance.

You can report fraud in the education sector or sign up for alerts through the DfE reporting service. For further information, read the DfE’s counter fraud guidance.

 

 

 

fyi

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...