Menu
Browse

Cyber Incident Victim: AOA

Date

Mar 2017

Location

United Kingdom

Status

Historical

Updated

2026-08-04 02:51

Timeline
Occurred
Undetermined
Discovered
Mar 2017
Disclosed
Apr 2017
Resolved
Pending
Summary

The exam board AQA suffered a cyber‑attack that resulted in the theft of personal data belonging to tens of thousands of current and former examiners. The compromised information included names, addresses, phone numbers, answers to security questions and passwords for other online examiner systems, although no bank details, school or pupil data or exam material were stored on the affected systems. After initially believing no data had been taken, the board conducted a forensic analysis that confirmed the breach, took the affected systems offline, began contacting affected examiners, reset passwords and reported the incident to the Information Commissioner’s Office and Ofqual for investigation.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 3 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On March 21 2017 AQA became aware of a cyber‑attack on its online systems and immediately took the affected systems offline to address security issues, an action described by the board as a precautionary measure to limit any potential impact. Initially AQA indicated that no data appeared to have been stolen, but after conducting a thorough forensic analysis on April 6 2017 the organization discovered that personal information had indeed been accessed, revealing that the breach had occurred more than two weeks before the discovery. The article states that the attack resulted in the theft of data relating to approximately 64 000 current and former examiners, including their names, addresses, personal telephone numbers, passwords and answers to security questions stored on AQA’s systems. The compromised information did not contain bank details, data belonging to schools or pupils, or any examination material, as explicitly noted by AQA in its public statement.

Cyber Incident Image

The stolen data comprised names and contact details, responses to security questions, and passwords for other online examiner systems, all of which AQA confirmed were being reset as part of its response. AQA reported that it was contacting every examiner whose personal details had been taken to inform them of the breach and to offer support, while simultaneously notifying Ofqual and the Information Commissioner’s Office of the incident. The board’s internal investigation and the steps taken to secure its networks. AQA emphasized that its existing cyber‑security measures, although unable to prevent the malicious activity, had helped to contain the scope of the breach and limit the damage to the examiner community.

In the aftermath, the Information Commissioner’s Office confirmed that it was aware of a potential data breach involving AQA Education and announced that it would make enquiries into whether the exam board had complied with the requirements of the Data Protection Act, noting that any findings of non‑compliance could lead to actions ranging from a warning letter to a financial penalty. AQA’s chief information officer, David Shaw, expressed disappointment that the breach had occurred despite the board’s efforts to maintain secure systems and apologized to the affected examiners for the inconvenience caused. The e‑AQA platform used by schools and colleges was taken offline as a precautionary step, although AQA clarified that this system was not part of the attacked infrastructure.

The article situates this event within a broader trend of cyber‑threats targeting the education sector, referencing a prior warning issued in January 2017 about scammers impersonating government officials to obtain sensitive information and hold computer files for ransom, thereby highlighting the ongoing challenges faced by educational institutions in safeguarding personal data.

Sources
Sources available to members
1 source