In the 2025/26 Department for Science, Innovation & Technology Cyber security breaches survey, 92% of UK primary schools reported phishing attempts targeting their establishments, with education now 43% more likely to experience cyber-attacks than UK businesses.
The consequences extend far beyond IT disruption. A single successful phishing attack costs schools an average of £27,000 in recovery costs, not including potential ICO fines reaching £500,000 for data breaches.
For School Business Managers and Trust CEOs managing already-stretched budgets, knowing how to spot phishing attempts before they take root is key to preventing devastating financial and reputational effects.
In this article, we’ll take you through the common tactic's scammers use against those working in education, giving you best practice tips we share with over 1800 education establishments, so you can recognise sophisticated phishing attempts and strengthen your teams against cyber-attacks.
Phishing is where scammers attempt to imitate trusted organisations (such as Microsoft, DfE, Local Authorities, suppliers, colleagues, service portals etc.) to trick recipients into releasing sensitive information or making unauthorised payments.
Many phishing scams in schools are sent by email, however SMS, voice calls and QR codes are becoming increasingly popular methods.
Phishing emails create a false sense of urgency for victims by asking them to take an action such as:
If a victim clicks on a link within a phishing email, it could trigger a false sign-in page designed to imitate official pages or install malicious software. This grants cybercriminals the ability to:
In school or trust environments where staff deal with many requests daily, even a temporary lapse in judgement could provide cybercriminals with access to sensitive pupil data, disable accounts across whole trust networks, or result in staff losing their wages.
Cyberattacks can spread across MAT’s quickly, so all staff should know to verify the authenticity of any requests for information or updates to payment details through a trusted channels before taking actioning.
With technology evolving at a rapid rate, phishing attacks and school cybersecurity threats are growing more sophisticated. Now more than ever, it’s essential for all staff across your organisation to know the signs of cybercrime.
Here are some examples of phishing tactics we see commonly see from scammers targeting UK schools:
Peak times for phishing attempts
While cybercriminals can strike at any time, scammers targeting education know to target schools facing busy periods. We typically see spikes in reported attacks from our customers during exam seasons, or when schools prepare for the end of term.
Where teams are pre-occupied with an influx of tasks and deadlines, it’s easy to become susceptible to phishing attempts. The threat of losing account access during a deadline filled week, or missing an urgent request from a CEO prevent important tasks from being completed.
Remind staff to remain vigilant, even while busy.
Though phishing attempts can now take many forms, these 8 safeguarding tips can be used by you, and your teams to assess any suspicious requests that may arise.
If you weren’t expecting an email, request, invoice, document share, or password reset, treat it as suspicious.
Fraudsters often make subtle changes to email addresses. Look out for:
Be wary of emails that claim to come from colleagues but are sent from an external address.
This will allow you to preview the destination. If the address looks unusual, shortened, misspelled, or doesn’t match the organisation it claims to be from, report the request according to your internal IT procedure.
Requests using language such as “Immediate action required”, “account will be suspended today”, “final warning”, “payment overdue” is a classic phishing tactic that preys on the false urgency to drive action. Be wary of any requests that feel forceful and verify these using trusted contact details if you deem it necessary.
Be cautious of any messages asking you to:
Be wary of email attachments you are not expecting, such as:
These should be treated as high risk and verified with the sender using known contact details, not the ones provided in the email.
If an email asks you to scan a QR code to “log in” or “verify” and account, treat this like you would a link: Don’t scan unless you have verified the sender via a known trusted route.
Cybercriminals will often prompt sign-in by providing links to login pages. Though the link may look like the genuine source, it can easily be mimicked, allowing fraudsters to steal your log-in data if supplied. If you’re unsure, never use the link in the email. Always sign-in using the official source page.
Defence against fraudulent activity is as strong as your least vigilant team member. And with cybercrime methods constantly evolving, keeping your staff educated about the latest scams and fraud tactics will reduce everybody's risk of falling victim.
Though these tips and tricks may come in useful, we understand that school life is fast paced. Providing regular training for staff, or running security tests can be difficult to balance with team workloads.
Our partners Secure Schools work exclusively with schools, providing training, audits and extensive system testing to reduce the risks of cyber threats for schools and trusts.
With over 85,000 cyber security courses delivered to staff across trusts, Secure Schools have a range of tiered packages on offer, to make sure that you have the right level of support in place to improve cyber-resilience in staff.
Not sure where to start? Secure Schools offer a free cyber score check to help you benchmark your digital systems against DfE cyber security standards and offers free insights to where you can continue to improve.
Discover your free cyber score
Cybersecurity measures aren’t just a back-office issue, but a shared responsibility across your entire school or trust network. By keeping your staff alert, and informed about the latest threats, you can drastically reduce your chances of cyberattacks and keep your data safe.