The Department for Education has confirmed a data breach affecting more than 607,000 records, after a group calling itself ExfilSquad claimed to have stolen names, job titles, work email addresses and phone numbers belonging to head teachers, university staff and government officials. The data came from the DfE’s Help Desk Self-Service Portal and its Turing Scheme Portal — and the attackers didn’t need a software vulnerability to get in. Reports point to a social engineering attack aimed at an internal helpdesk, the kind of scam that talks a support agent into handing over access rather than hacking through a firewall. The DfE has referred the incident to the ICO and is working with the NCSC and the National Crime Agency.

It’s a government department this time, with the scale and headlines that come with it. But the method — not the target — is what should worry small business owners. Helpdesk social engineering doesn’t require deep technical skill or a zero-day exploit. It requires a plausible phone call, a stressed or trusting employee, and a process with no hard stop built in.

Why this hits small businesses harder than headlines suggest

Large organisations at least have an IT security team and an incident response plan when something like this happens. Most SMEs don’t. If someone rings your office claiming to be from your IT provider, your bank, or a supplier and asks a member of staff to reset a password or share a one-time code, there’s often no second person to check with and no documented process to fall back on. Attackers know this, which is exactly why helpdesk and support-desk pretexting has become such a reliable route in — it’s cheaper and faster for them than finding a technical flaw, and it works against organisations of every size.

This pattern isn’t isolated to the DfE. Similar helpdesk-focused social engineering has been behind several of the biggest breaches of the past two years, precisely because it sidesteps the technical controls businesses spend most of their security budget on — firewalls, patching and endpoint protection do nothing to stop an attacker who simply asks a human being to let them in. And the more convincing generative AI voice and text tools get, the more convincing that ask becomes. A caller who sounds exactly like your usual IT contact, using details lifted from a LinkedIn profile or a leaked email signature, is a harder problem than the generic phishing email most staff have already learned to spot.

What to actually change this week

Start with the request types that should never be actioned on a single phone call: password resets, MFA re-enrolment, and changes to where invoices get paid. Any of these should require a callback to a number you already have on file — not the number the caller gives you — or verification through a second channel entirely. Write this down as a one-page policy, however small your team is, because “we’d obviously check” tends to break down under exactly the kind of pressure a good social engineer applies. If you outsource IT or use a managed provider, ask them directly what your callback and verification process is for account resets, and don’t assume it exists just because nobody’s raised it as a problem.

It’s also worth a genuine five-minute conversation with anyone in your business who answers the phone or deals with support requests — reception staff, junior admin, whoever’s newest — since they’re disproportionately the ones targeted precisely because they’re least likely to push back on an authoritative-sounding caller. KeepSafe monitors for exactly this kind of incident pattern across UK businesses, flagging the early signs of account compromise before a stolen credential turns into a full breach.

If you suspect an account has already been reset or accessed through a scam call, force a password change and MFA re-enrolment immediately, check sign-in logs for anything unfamiliar, and tell the rest of the business so the same caller can’t simply try someone else next. If customer or supplier data might have been exposed, UK GDPR obligations mean assessing whether to report to the ICO within 72 hours of becoming aware — don’t wait until you’re certain, since the assessment itself is part of what that clock is for.

The takeaway

A department with far more security resource than most SMEs was still beaten by a phone call, not a hack. If your business doesn’t have a written rule for what happens when someone rings asking to reset access, that’s the gap this story is pointing at — and it costs nothing to close it before someone tries the same thing on you.