AndyCrow Posted August 21, 2025 Posted August 21, 2025 Dear Client We are writing to inform you, as the data controller, of a potential data breach that has occurred involving data processed by Single Central Record Ltd, acting as the data processor. We are committed to maintaining the highest standards of data protection and transparency, and it is in this spirit that we provide you with the following details. Description of the Incident On 17th August 2025 we were notified by Intradev, our external software supplier, that a part of their system had been subject to unauthorised access. The incident itself occurred around 31st July 2025. Intradev confirm that certain files that relate to personal data were copied from their systems. Our own network and servers were not compromised. We are actively investigating why Intradev had copies of some of our data in their systems. Nature of the Data The data potentially affected by this breach includes personal identification information. At this stage, we are conducting a thorough analysis to determine the full scope of the data involved. From our assessment so far, the scope of the data appears to be limited to an audit table used to record certain changes or actions made in the Single Central Record. Potential Impact The potential impact on the data subjects may include identity theft. We are actively assessing the situation to understand the extent of the impact and will keep you informed of any significant developments. Immediate Actions Taken Upon discovery of the breach, we immediately obtained a report from Intradev detailing the nature of wthe breach. We have undertaken a review of our own systems, which have not been affected. Although we are not the data controller, we have been pragmatic and made a report to the Information Commissioner's Office (ICO). Next Steps We recommend that you, as the data controller, consider reporting the matter to the ICO and to notify potentially affected data subjects. You can report the matter to the ICO on their website https://ico.org.uk/for-organisations/report-a-breach and contact them for advice on 0303 123 1113. We will do our best to assist you to address this situation and mitigate any potential harm to the data subjects. Should you require more detailed information to fulfill your own data controller obligations, please contact us. We are prepared to assist you in assessing the full nature of the data upon your request. Contact Information For further communication regarding this matter, please contact us on [email protected] or 0151 606 5101. We are available to discuss any concerns you may have and to provide additional information as it becomes available. We take this matter very seriously and are committed to resolving it promptly and effectively. Thank you for your attention to this urgent issue. Sincerely, SCR Team
Sonic007 Posted August 26, 2025 Posted August 26, 2025 Well this is yet another piece of crap to deal with for the start of term, informing members of staff of the data breach and logging with ICO. Yay!
DHRose Posted August 29, 2025 Posted August 29, 2025 I have a data breach resource kit for this incident if anyone thinks it would be useful. The kit is free and includes risk grids, letter template, governor briefing and school comms. It is in draft form, does not constitute legal advice and it is recommended that all actions are confirmed with your school DPO prior to use. Hope it helps a little. _OnlineSCR data breach pack.zip
andy_b Posted August 29, 2025 Posted August 29, 2025 1 hour ago, browolf said: just seen this on reddit as well 😧 Saw it in r/UKPersonalFinance too.
Zzyzx. Posted September 2, 2025 Posted September 2, 2025 More concerning is that the breach happened in July, but schools were only notified at the end of August. My school wants to switch supplier in light of this. Who do other schools use for this kind of thing?
tom_newton Posted September 2, 2025 Posted September 2, 2025 I'm told a lot of folk prefer a google sheet or something roughly equivalent! Is that true? There's a degree to which building a company around something this niche is asking for data breach issues
robintech Posted September 2, 2025 Posted September 2, 2025 Just got this from Exclaimer wonder if its the same thing Incident Summary We recently identified unauthorized data access through Drift, an AI-powered chatbot owned by Salesloft, which had been connected to our Salesforce and Zendesk platforms. Once we became aware of the issue, we immediately disabled all Drift integrations. Our investigation, conducted in coordination with Zendesk and Salesloft, confirmed that certain Zendesk and Salesforce data was accessed. To be clear, Exclaimer’s own systems were not breached. The accessed data included business email addresses associated with your organization, including this address.
psydii Posted September 5, 2025 Posted September 5, 2025 Does anyone have a real handle on the scope and scale of this incident? The back-end provider seems to have been used by several services, across several sectors. It feels to me like it could be somewhere between everyone with a dbs check, or only a few thousand people. Anyone found they are on the list? (though maybe we don't want to say, just in case cross referencing the users from here against the list provides further advantage to the bad-guys)
andy_b Posted September 5, 2025 Posted September 5, 2025 We use a different system, but our DPO service sent this mailshot this afternoon Quote What happened? On 17th August 2025, the Online SCR was notified by its software supplier, Intradev Ltd, about a cyber-attack that resulted in unauthorised access and copying of personal data records processed on behalf of education settings. The breach was traced to the supplier’s internal infrastructure, which Online SCR uses to help deliver its services. It is important to be aware that the internal systems operated by Online SCR were not directly compromised by this incident and they have informed their customers that services can continue as normal. The Online SCR has duly reported this personal data breach to Information Commissioner’s Office (‘ICO’) and taken a proactive approach to notify their affected customer base. Further updates about the incident are to be provided to their affected customers as their investigation progresses. What happened? On 17th August 2025, the Online SCR was notified by its software supplier, Intradev Ltd, about a cyber-attack that resulted in unauthorised access and copying of personal data records processed on behalf of education settings. The breach was traced to the supplier’s internal infrastructure, which Online SCR uses to help deliver its services. It is important to be aware that the internal systems operated by Online SCR were not directly compromised by this incident and they have informed their customers that services can continue as normal. The Online SCR has duly reported this personal data breach to Information Commissioner’s Office (‘ICO’) and taken a proactive approach to notify their affected customer base. Further updates about the incident are to be provided to their affected customers as their investigation progresses. Who is affected by the breach? If your school and/or Trust uses Online SCR, you may have been impacted by the breach. During the summer school holidays, you should have been contacted by Online SCR and received an email update from them detailing what has happened with confirmation as to how the breach has affected you and your staff. However, due to school holidays and staff being on leave, some communications may not yet have been received. We also encourage you to check your junk folder for any correspondence you may have received. In each communication, you should have received an Excel Spreadsheet from the Online SCR that contains a tailored breakdown of what personal information was compromised; how many people have been affected; and what types of information are at risk. If you have not been contacted by Online SCR to date, or no longer use this service provider, then you may not have been affected by the breach. However, we recommend considering getting in touch with the Online SCR to help confirm this point. For any questions about the breach, or to confirm if you have been affected, the Online SCR has recommended you get in touch with them by emailing: [email protected] What information is at risk? We are currently awaiting more details from Online SCR. However, we understand that the breach may have affected some or all the following information: Name Phone number Date of birth Email address Postal address Place of birth National Insurance number Passport number Driving licence number QTS numbers (teaching qualification) The affected information does NOT include: Financial details Passwords Medical information Information on any disclosures (e.g. criminal records) Information about protected characteristics (e.g., ethnicity, disability, sexual orientation, marital status) The personal data that was accessed was in text format only. No original documents or images were affected. Recommended Next Steps If your School or Trust use Online SCR, or have been a customer with this provider in the past, we recommend you consider taking the following steps: Confirm Risk Impact: Contact the Online SCR to verify whether your organisation’s data has been affected by this breach. You should also check if you have received any emails from this provider – as some of these notifications can end up in your spam/junk folders. Notify the ICO: As the data controller, your school or trust must report the breach to the ICO within 72 hours of becoming aware of it. Should you need to report this breach to the regulator, you can include the SCR’s breach reference in your report - IC-415209-Y2T2 However, it is important to stress you may not need to do this in every case. We recommend you contact our team or your local DPO first to verify if any individuals are at higher risk because of the breach. Not all affected individuals are necessarily in this group – so best to check before reporting. Inform Data Subjects: Notify affected individuals at a higher risk of harm with clear and supportive guidance. You can use and adapt the Data Breach Notification Template Word document supplied by the Online SCR to help notify affected individuals about the following: Explain what information is at risk because of the breach; and Practical steps on how to mitigate higher risks of scams (e.g., phishing attempts); and Provide contact details for support from third party organisations (such as Action Fraud or Credit Agencies). If you do not have a copy of this Data Breach Notification Template, or you prefer to tailor the wording before contacting any affected staff, please get in touch with us so we can provide you with further support. Review Contracts: you should review your Service Agreement with the Online SCR to consider any necessary legal or financial recourse. XXX can support with the review of any terms governing data protection. However, you may wish to seek independent legal advice for other contractual terms you feel are unclear. Update DPIAs: If you have not done so already, schools and Trusts using Online SCR should carry out or update their Data Protection Impact Assessment (‘DPIA’) for use of this service to document this new risk. Assess Liability: some of your staff, who must be made aware of the breach, may warn you or decide to issue a claim for compensation against their employer. This can be a typical reaction after receiving such news in many cases. We recommend education settings prepare themselves for this possible risk.
browolf Posted September 5, 2025 Posted September 5, 2025 The company that our school have a contract with is "Single central record Ltd". They use another company called "Access Personal Checking Services (APCS)" to do the actual DBS checks. But many news articles only mention APCS and the software they use made by Intradev was where the breach happened reportedly. https://www.theregister.com/2025/08/22/apcs_breach/
andy_b Posted April 2 Posted April 2 Quote Fraudulent letter – DfE “National Regulatory Notice” We are sorry to contact you over the holiday period, but we thought you should be aware that some academy trusts have received a letter presented as a DfE “National Regulatory Notice”. It includes a ministerial signature and claims there has been a data breach involving Online SCR / Intradev. This letter has been confirmed by the DfE as fraudulent and has not been issued by the minister’s office. All trusts must not: follow any instructions in the letter share data or comply with the directions All trusts must: ensure senior leaders, governance leads and administrative teams are aware report any receipt of the letter to your usual DfE contact or contact the DfE through GOV.UK If anyone has already acted on the letter, notify your trust’s IT or security lead. You should also report it through your usual process and monitor systems for unusual activity. Follow the Academy trust handbook for guidance. You can report fraud in the education sector or sign up for alerts through the DfE reporting service. For further information, read the DfE’s counter fraud guidance. fyi
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now