Cyber Incident Victim: AOA
Timeline
Summary
The exam board AQA suffered a cyber‑attack that resulted in the theft of personal details of tens of thousands of examiners. Stolen information included names, addresses, phone numbers, answers to security questions and passwords for other online examiner systems, while bank details, school or pupil data and exam material were not compromised. After initially believing no data had been taken, a forensic analysis revealed the breach, prompting the affected systems to be taken offline and the Information Commissioner’s Office to open an investigation under the Data Protection Act. The board began contacting all affected examiners, resetting passwords and notifying Ofqual and the ICO, and the e‑AQA platform was taken offline as a precaution although it was not part of the attack. The incident is part of a broader trend of cyber threats targeting the education sector, with warnings issued about scammers attempting to obtain sensitive information.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 3 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On March 21, 2017, AQA became aware of a cyber-attack on its online systems and immediately took the affected systems offline to address security issues. Initial assessments indicated that no data had been compromised, but a subsequent forensic analysis conducted on April 6 revealed that personal information had been accessed. The attack resulted in the theft of data relating to approximately 64,000 current and former examiners, including names, addresses, personal telephone numbers, passwords, and answers to security questions used for other online examiner systems. The compromised data did not contain bank details, information about schools or pupils, or any examination material.

Upon discovering the breach, AQA began contacting all examiners whose details had been taken and informed them that passwords for the affected systems were being reset. The organization also reported the incident to Ofqual and the Information Commissioner’s Office (ICO). AQA’s chief information officer, David Shaw, expressed disappointment that the breach occurred despite existing security measures, noting that those measures helped limit the impact of the malicious activity. As a precaution, the e‑AQA system used by schools and colleges was taken offline, although AQA confirmed that this system was not part of the attacked infrastructure.
The ICO confirmed awareness of a potential data breach involving AQA Education and stated that it would make enquiries to determine whether the exam board had complied with the Data Protection Act. Depending on the findings, the ICO could issue a warning letter or impose a fine. AQA reiterated that it takes cyber security seriously and maintains protective measures for personal information, while acknowledging that the breach highlighted a need for continued vigilance. The incident was noted as part of a broader trend of cyber‑attacks targeting the education sector, following earlier warnings in January about scammers impersonating government officials to extort data.
