Resources | EPM

Protecting schools from phishing scams: 8 essential tips for education leaders

Written by Jodie Milner | 24 Jul 2026

Cybercrime is on the rise in education. What can you do to safeguard your schools or trusts systems against cyberattacks and prevent your teams falling for phishing scams? 

In the 2025/26 Department for Science, Innovation & Technology Cyber security breaches survey, 92% of UK primary schools reported phishing attempts targeting their establishments, with education now 43% more likely to experience cyber-attacks than UK businesses.  

The consequences extend far beyond IT disruption. A single successful phishing attack costs schools an average of £27,000 in recovery costs, not including potential ICO fines reaching £500,000 for data breaches.

For School Business Managers and Trust CEOs managing already-stretched budgets, knowing how to spot phishing attempts before they take root is key to preventing devastating financial and reputational effects.

In this article, we’ll take you through the common tactic's scammers use against those working in education, giving you best practice tips we share with over 1800 education establishments, so you can recognise sophisticated phishing attempts and strengthen your teams against cyber-attacks.

Read on for 

  1. What is phishing? 
  2. Common phishing tactics targeting schools and trusts 
  3. 8 essential steps to spot and prevent phishing in schools 
  4. How to build phishing resistant teams 
  5. Phishing protection support for schools and trusts

1. What is phishing? 

Phishing is where scammers attempt to imitate trusted organisations (such as Microsoft, DfE, Local Authorities, suppliers, colleagues, service portals etc.) to trick recipients into releasing sensitive information or making unauthorised payments.

Many phishing scams in schools are sent by email, however SMS, voice calls and QR codes are becoming increasingly popular methods.

Phishing emails create a false sense of urgency for victims by asking them to take an action such as:

  • Resetting a password
  • Re-registering an account
  • Confirming their mailbox
  • Reviewing a document
  • Unlocking their account
  • Restoring access to resources.

If a victim clicks on a link within a phishing email, it could trigger a false sign-in page designed to imitate official pages or install malicious software. This grants cybercriminals the ability to:

  • Access accounts and systems you use
  • Intercept emails
  • Request payroll or bank detail changes
  • Target colleagues within your school or trust through ‘trusted sender’ attacks.

In school or trust environments where staff deal with many requests daily, even a temporary lapse in judgement could provide cybercriminals with access to sensitive pupil data, disable accounts across whole trust networks, or result in staff losing their wages.

Cyberattacks can spread across MAT’s quickly, so all staff should know to verify the authenticity of any requests for information or updates to payment details through a trusted channels before taking actioning.

2. Common phishing tactics targeting schools and trusts

With technology evolving at a rapid rate, phishing attacks and school cybersecurity threats are growing more sophisticated. Now more than ever, it’s essential for all staff across your organisation to know the signs of cybercrime.

Here are some examples of phishing tactics we see commonly see from scammers targeting UK schools:

  • False IT Department requests- A simple request asking to ‘verify an account’ or ‘install an update’ may seem legitimate, however these should always be verified with your internal IT teams first.
  • Headteacher or SLT impersonation- Urgent requests that appear to come from senior colleagues could be ‘trusted sender’ attacks. These are common via SMS or phone call, especially where information on leadership teams is publicly available for scammers.
  • Supplier and invoice scams- Emails from suppliers may contain invoices, which are an effective PDF for scammers to disguise as malware. Always check the email address is credible before clicking on attachments.
  • Cloud service requests- Urgent requests from your school or trust cloud provider (Google, Microsoft 365 etc) to install software updates, confirm accounts or update your password should be verified with your IT team.
  • Payroll or HR change requests- Requests from employees asking to update bank account details are popular over holiday periods but could be fraudulent. Always verify requests with employees before updating.

Peak times for phishing attempts

While cybercriminals can strike at any time, scammers targeting education know to target schools facing busy periods. We typically see spikes in reported attacks from our customers during exam seasons, or when schools prepare for the end of term.

Where teams are pre-occupied with an influx of tasks and deadlines, it’s easy to become susceptible to phishing attempts. The threat of losing account access during a deadline filled week, or missing an urgent request from a CEO prevent important tasks from being completed.

Remind staff to remain vigilant, even while busy.

3. 8 essential steps to spot and prevent phishing in schools

Though phishing attempts can now take many forms, these 8 safeguarding tips can be used by you, and your teams to assess any suspicious requests that may arise.

1. Verify expected requests

If you weren’t expecting an email, request, invoice, document share, or password reset, treat it as suspicious.

2. Examine sender email addresses carefully

Fraudsters often make subtle changes to email addresses. Look out for:

  • One letter differences,
  • Extra characters,
  • Email addresses that use a different domain e.g: “.co” instead of “.com”, etc.
  • Share passwords, verification codes, or staff personal data with the sender.

Be wary of emails that claim to come from colleagues but are sent from an external address.

3. Hover over links before clicking

This will allow you to preview the destination. If the address looks unusual, shortened, misspelled, or doesn’t match the organisation it claims to be from, report the request according to your internal IT procedure.

4. Watch for urgency, pressure, or threats

Requests using language such as “Immediate action required, “account will be suspended today, “final warning, “payment overdue is a classic phishing tactic that preys on the false urgency to drive action. Be wary of any requests that feel forceful and verify these using trusted contact details if you deem it necessary.

5. Look for unauthorised requests

Be cautious of any messages asking you to:

  • Change bank details
  • Create or approve urgent payments
  • Purchase vouchers/gift cards

6. Be cautious with attachments

Be wary of email attachments you are not expecting, such as: 

  • ZIP files
  • Invoice files
  • Documents prompting you to “enable editing

These should be treated as high risk and verified with the sender using known contact details, not the ones provided in the email.

7. Watch for QR codes

If an email asks you to scan a QR code to “log in” or “verify and account, treat this like you would a link: Don’t scan unless you have verified the sender via a known trusted route.

8. Watch for third party sign in pages

Cybercriminals will often prompt sign-in by providing links to login pages. Though the link may look like the genuine source, it can easily be mimicked, allowing fraudsters to steal your log-in data if supplied. If you’re unsure, never use the link in the email. Always sign-in using the official source page.

What to do if you're unsure (Or you've already clicked a suspicious link) 
  • Don’t click anything further and don’t enter any details.
  • Verify the request using a trusted method (e.g. phone the sender using a known number or contact your IT support).
  • If you have clicked or entered details, you should change your password immediately and inform your IT team so they can check for account access and apply protective controls.

4. How to build phishing resistant teams

Defence against fraudulent activity is as strong as your least vigilant team member. And with cybercrime methods constantly evolving, keeping your staff educated about the latest scams and fraud tactics will reduce everybody's risk of falling victim.

Train your staff in fraud awareness

  • Implement regular cyber security training for all employees
  • Run phishing simulations to allow staff to implement training skills
  • Share clear guidance on how staff can report suspicious activity.

Review your technical protections
  • Run external tests against your IT systems to identify where gaps in security sit.
  • Review your firewall and web-filtering
  • Enable Multi Factor Protections (MFA) across staff accounts.

Review your internal policies
  • Nominate a Data Protection Officer (DPO) as your go to person for overseeing your school or trusts cybersecurity measures.
  • Review your reporting routes and incident response plans ensuring all staff are aware of the procedures to follow when reporting a phishing attempt, or wider security risk.

5. Phishing protection support for schools and trusts 

Though these tips and tricks may come in useful, we understand that school life is fast paced. Providing regular training for staff, or running security tests can be difficult to balance with team workloads.

Our partners Secure Schools work exclusively with schools, providing training, audits and extensive system testing to reduce the risks of cyber threats for schools and trusts.

With over 85,000 cyber security courses delivered to staff across trusts, Secure Schools have a range of tiered packages on offer, to make sure that you have the right level of support in place to improve cyber-resilience in staff.

Not sure where to start? Secure Schools offer a free cyber score check to help you benchmark your digital systems against DfE cyber security standards and offers free insights to where you can continue to improve.

Discover your free cyber score 

Conclusion

Cybersecurity measures aren’t just a back-office issue, but a shared responsibility across your entire school or trust network. By keeping your staff alert, and informed about the latest threats, you can drastically reduce your chances of cyberattacks and keep your data safe.