Essex-based Billericay School experienced a significant data security incident that compromised the sensitive personal information of its students, including their medical data and guardians’ contact details.
In a letter to parents last Friday, Essex-based Billericay School’s head teacher Patrick Berry said that during the half term holiday, the school suffered a significant “cyber/malware attack”. The school immediately launched an investigation, and engaged cyber security experts, to determine the nature and scope of the incident.
“Whilst the school has taken all of the precautionary security measures to deal with any such cyber threat, with industry standard firewalls, firmware and malware security, this attack has resulted in all of the school IT system being compromised and inaccessible by a complex encryption.
“Whilst our IT support staff are working hard to resolve the issue and have already made significant progress in restoring the required systems, the situation as it stands is significantly affecting our ability to operate the school safely and effectively,” reads the letter.
The school was closed for students of year 7,8,9 and 12, but gave students the option to use remote learning platforms such as Sparx, Tassomai, Educake, Oak Academy and BBC Bitesize.
In a separate letter sent to parents, head teacher Berry said that the school’s investigation has revealed that the sensitive personal information of its students and their parents and caregivers were compromised during the incident.
While the school is yet to identify “what specific data” was accessed or exfiltrated from its network, personal identifiable data of students including their names, addresses, basic medical notes, dates of birth and contact details for parents and carers were accessed during the incident.
Berry said the cyber security incident also impacted the school’s cashless catering system which means students will have to carry packed lunch on Tuesday and Wednesday. “We would expect to have resolved this issue within the next two days,” he said.
“We are working with Action Fraud, a branch of the Police to investigate this attack but please be vigilant when opening emails and webpages to avoid criminals harvesting user credentials via any email addresses we may hold for you.
“We would suggest that you take preventative action such as changing personal passwords,” Berry added.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543