Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Glossary
    • Whitepapers
  • Newsletter
  • + More
    • Conversations
    • Events
    • About
      • About
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
  • AI
  • Tech
  • Cybersecurity
  • Finance
  • DeFi & Blockchain
  • Startups
  • Gaming
Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Glossary
    • Whitepapers
  • Newsletter
  • + More
    • Conversations
    • Events
    • About
      • About
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
Dataconomy
No Result
View All Result

ICO warns of student cyberattacks on UK schools

More than 200 incidents have been investigated since 2022, including cases involving children as young as seven.

byAytun Çelebi
September 11, 2025
in Cybersecurity
Home News Cybersecurity

The Information Commissioner’s Office (ICO) has issued a warning about a concerning rise in students illicitly accessing their educational institutions’ IT systems. These actions, the ICO reports, are often driven by amusement or peer challenges.

The ICO emphasizes a perceived lack of awareness among educators regarding the risks posed by students with internal access to school networks, describing it as an “insider threat.” Data collected by the ICO indicates that a significant portion of cyber incidents and data breaches in education are attributable to student actions.

Heather Toomey, Principal Cyber Specialist at the ICO, highlighted the potential for seemingly harmless activities to escalate. Toomey stated,

Stay Ahead of the Curve!

Don't miss out on the latest insights, trends, and analysis in the world of data, technology, and startups. Subscribe to our newsletter and get exclusive content delivered straight to your inbox.

“What starts out as a dare, a challenge, a bit of fun in a school setting can ultimately lead to children taking part in damaging attacks on organisations or critical infrastructure.”

This statement underscores the ICO’s concern that youthful experimentation can evolve into more serious cyber offenses with broader implications.

This warning follows a series of high-profile cyberattacks on companies like Marks and Spencer (M&S) and Jaguar Land Rover. Investigations revealed the involvement of teenage hackers, raising concerns about the increasing prevalence of youth in cybercrime.

Student-led breaches in education

Since 2022, the ICO has investigated 215 incidents of unauthorized access and data breaches originating within educational institutions. Children were responsible for 57% of these incidents. The remaining breaches are suspected to have been perpetrated by staff, third-party IT service providers, and other entities with authorized system access.

Data indicates that almost one-third of the investigated breaches involved students gaining unauthorized access to staff computer systems. These breaches often occurred through methods like guessing passwords or illicitly obtaining login credentials from teachers, highlighting the relative simplicity of some exploited security vulnerabilities.

Case examples of student cybercrime

One case involved a seven-year-old child implicated in an undisclosed data breach. Following the incident, the child was referred to the National Crime Agency’s Cyber Choices program, which educates young people about the consequences and legal ramifications of cybercrime.

In a separate instance, three Year 11 students (aged 15-16) illegally accessed school databases containing personal information for over 1,400 fellow students. They used internet-downloaded hacking tools to bypass password protections, citing an interest in cybersecurity and a desire to explore technical capabilities.

Another incident involved a student gaining unauthorized access to a college’s databases using a teacher’s login credentials. This access was used to modify or delete personal information for over 9,000 staff, students, and applicants. Compromised data included names, home addresses, academic records, health information, safeguarding and pastoral logs, and emergency contact details.

Rising cyber threats to educational institutions

According to the government’s latest Cyber Security Breaches Survey, educational institutions face an increasing threat landscape. The survey revealed that 44% of schools reported experiencing a cyberattack or data breach within the past year, underscoring the sector’s growing vulnerability.

The ICO also highlighted the role of youth cybercrime culture, noting its increasing connection to English-speaking teen gangs. The past year has seen arrests in both the UK and the US of young individuals allegedly involved in hacking campaigns targeting major organizations, including MGM Grand Casinos, Transport for London (TfL), Marks and Spencer, and the Co-op.


Featured image credit

Tags: cyberattacksICO

Related Posts

Cybersecurity shifts from network to human element

Cybersecurity shifts from network to human element

September 11, 2025
FastNetMon mitigates 1.5 Gpps DDoS attack

FastNetMon mitigates 1.5 Gpps DDoS attack

September 11, 2025
Hackers use Apple Calendar invitations to deliver phishing scams through notes field

Hackers use Apple Calendar invitations to deliver phishing scams through notes field

September 11, 2025
ChillyHell malware continues targeting Mac users with advanced evasion tactics

ChillyHell malware continues targeting Mac users with advanced evasion tactics

September 11, 2025
MIT Sloan: 80% of ransomware attacks use AI

MIT Sloan: 80% of ransomware attacks use AI

September 11, 2025
AWS Security in 2025: The intersection of AI, data and cloud protection

AWS Security in 2025: The intersection of AI, data and cloud protection

September 11, 2025

LATEST NEWS

AGI ethics checklist proposes ten key elements

ICO warns of student cyberattacks on UK schools

Ant Group unveils their own Tesla Optimus competitor, R1 humanoid robot

Google Gemini now transcribes audio files

Cybersecurity shifts from network to human element

Meta expands Community Notes with user alerts

Dataconomy

COPYRIGHT © DATACONOMY MEDIA GMBH, ALL RIGHTS RESERVED.

  • About
  • Imprint
  • Contact
  • Legal & Privacy

Follow Us

  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Glossary
    • Whitepapers
  • Newsletter
  • + More
    • Conversations
    • Events
    • About
      • About
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
No Result
View All Result
Subscribe

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy Policy.