Cyber Incident Victim: Nottinghamshire schools
Date:
Mar 2021
Location:
United Kingdom
Summary
A cyber attack targeting the Nova Education Trust disrupted IT systems across 15 affiliated secondary schools, forcing a network shutdown as a preventative measure. The incident prevented access to emails, websites, and remote teaching capabilities, requiring students to rely on external educational platforms while the trust communicated updates via its website and school Twitter feeds.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 2 techniques |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On March 3, 2021, Nova Education Trust, which manages IT systems for 15 secondary schools across Nottinghamshire, experienced a cyber attack that forced an immediate shutdown of its networks. The Trust implemented preventative measures by disabling all affected systems, resulting in a total loss of access to emails, phone services, and school websites. This disruption occurred during school hours, abruptly halting live teaching sessions and preventing the upload of new learning materials. By 8:15 AM that day, the Trust issued a public statement via its website acknowledging the incident and advising students to follow their regular timetables using alternative study methods. Remote learning capabilities were entirely incapacitated, leaving educators unable to deliver virtual instruction or distribute digital resources through standard channels.

The attack impacted all institutions under the Trust’s umbrella, severing critical communication infrastructure and forcing operational adjustments. Affected schools directed students to consolidate recent lessons using third-party platforms like BBC Bitesize, Oak Academy, GCSE Pod, and Seneca while systems remained offline. The Trust committed to providing ongoing updates through its website and individual school Twitter accounts, though no restoration timeline was provided in the initial communication. No details regarding the attack vector, perpetrator identity, or potential ransom demands were disclosed publicly. Educational continuity relied entirely on external e-learning resources during the outage, with no indication of data theft or secondary exploitation attempts mentioned in available reports. The Trust’s response focused exclusively on containment through system isolation and alternative communication channels while investigations continued.
