
Thomas Hardye School in Dorchester suffered a ransomware attack that crippled its internal IT systems and disrupted online activities.According to Dorset Live, threat actors targeted the school on Sunday, encrypted its systems and demanded a ransom in exchange for a decryption key. The school has, however, decided against paying the ransom and is working with the National Cyber Security Centre and police to investigate the incident.The cyber attack has affected the school’s main server, affecting all connected systems and services including canteen payments, pupil payments for other items which require fingerprint technology, electronic diaries, records and messaging.In a message to all guardians, Nick Rutherford, head teacher of Thomas Hardye School, said, “We are in liaison with our school Data Protection Officer and this data breach has been reported to the Information Commissioners Office (ICO) in line with requirements of the Data Protection Act 2018/GDPR. Every action has been taken to minimise disruption and data loss.“The school will be working with Wessex Multi-Academy Trust, IT team and other relevant third parties (Department for Education, National Cyber Security Centre and police) to restore functionality and normal working as soon as possible.”The school has decided to carry on with the ongoing exams and teachers have been asked to adapt themselves to manual mode of teaching till the school’s IT systems are up and running.“The school will remain open with teaching and learning being adapted accordingly. Please be reassured that examinations will continue to run as normal with contingencies in place for those students who have access arrangements,” Rutherford said.Guardians have been asked to contact the school via phone calls to report student absence and other emergencies as staff can’t access emails currently.“Staff will not have access to previous emails or online calendars, therefore, should you have made prior arrangements to meet with staff this week it may be worth phoning the school beforehand to check that our colleagues are aware. We will continue to assess the situation and update parents/carers as necessary by Groupcall until our email is restored,” Rutherford added.Commenting on the news, Erfan Shadabi, cybersecurity expert at Comforte AG, said, “Educational institutions are lucrative cyber-targets, they often possess valuable and sensitive data, including student records, financial information, and research data. Additionally, the interconnected nature of education systems, with multiple users and devices accessing network resources, can provide entry points for attackers to infiltrate these systems.“These institutions are known for their limited cybersecurity resources and budget constraints. This makes them attractive targets, as attackers perceive them as easier targets with potentially weaker defences compared to larger organisations.“Education centres must recognise the evolving cybersecurity landscape and take proactive steps to secure their data,” Shadabi added.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543