InfoSec / Cyber

Cyber attack written in computer text on a computer in red

Cyber Attack: Leytonstone School

This article is about a recent cyber attack on Leytonstone School.  The school in Waltham Forest has been closed since half term after it was targeted and a significant amount of personal data was accessed.

The school is still closed to all pupils other than those taking their GCSEs because the school currently does not have a single central record (SCR), sometimes referred to as a single central register.  An SCR is a statutory requirement for all schools and academies in England and Wales to keep and maintain one single record of pre-appointment vetting checks, regulated activity and recording information of all staff. The record is normally kept up to date by a member of the admin staff, but overall responsibility lies with governors (or equivalent) and delegated to headteachers.  It is an essential safeguarding document and must be maintained, reviewed and audited on a regular basis.  It will probably be one of the first documents that Ofsted will ask to see.  Any guidance relating to the SCR should also be read in conjunction with the current version of the Keeping Children Safe in Education (KCSIE) document.

There is no defined format for the SCR and most schools hold it electronically as a password protected Excel document.  As well as employees, it should also include:

  • any volunteer who is in regulated activity
  • people brought into the school to provide regular additional teaching or instruction but who are employed by another organisation such as peripatetic music teachers, sports coaches etc.
  • supply teachers
  • contract staff such as cleaners or caterers
  • Governors
  • Members of the proprietor body (trustees or directors) in independent schools including academies

As a result of the cyber attack at Leytonstone School there is also no WiFi and phone system, but it is the missing SCR that prevents the school from opening.  Our advice would be to always ensure there are secure offsite (cloud) backups of essential files, in addition to local backups.  The security of the SCR should be part of the school's business plan which should be discussed regularly at governing body meetings.  Review: {article title="Cyber responsibilities for Governors/Trustees in schools"}[link][title][/link]{/article} alongside Governors and Data Best Practice Area to understand how governor responsibilities relate to business continuity and cyber strategy.

View our Information & Cyber Security Best Practice Library for cyber help and guidance.

Download our Business Continuity Template.

We would also recommend viewing the National Cyber Security's pages that provide cyber security advice for schools, which includes free training: NCSC Cyber Security training for schools.
We provide additional Cyber Security Training: How to avoid a data breach: Information and Cyber security.

Further details about what has happened at the school can be viewed in this article by the Evening Standard: Leytonstone School forced to close after IT system hacked.

What to do in the event of a Cyber Attack 

Incidents or attacks where any security breaches may have taken place, or other damage was caused, should be reported to an external body. 

The SLT digital lead will be responsible for assigning someone to report any suspicious cyber incidents or attacks. This person will need to report this to: 

  • Action Fraud on 0300 123 2040, or the Action Fraud website 
  • the DfE sector cyber team at This email address is being protected from spambots. You need JavaScript enabled to view it. 

You may also need to report to: 

You must act in accordance with: 

Police investigations may find out if any compromised data has been published or sold and identify the perpetrator. 

Preserving evidence is as important as recovering from the crime.

Forward suspicious emails to This email address is being protected from spambots. You need JavaScript enabled to view it.. Report SMS scams by forwarding the original message to 7726 (spells SPAM on the keypad).

Little Guide to ACTION FRAUD

Search