Schools across the Thames Valley area are being targeted by criminals attempting to access staff payroll accounts, according to a warning issued by the South East Cyber Crime Unit's Cyber Protect team. In several confirmed cases, the attacks have succeeded, leaving affected staff without their pay after criminals diverted their salaries elsewhere.
How the Fraud Works
The method being used is methodical rather than opportunistic. Criminals gain access to an individual's payroll account, then work through a sequence of changes designed to lock the genuine account holder out and redirect their income:
- Access the payroll account, likely using stolen, guessed, or reused credentials.
- Reset the password, cutting off the legitimate user's usual route back in.
- Change the associated contact details, so any security alerts or verification messages go to the criminal instead of the staff member.
- Change the bank details, redirecting future salary payments to an account controlled by the attacker.
By the time the fraud is discovered, the victim's payslip may have already gone to the wrong account, and their ability to recover access has been deliberately undermined.
What Schools and Staff Should Do Now
Given the pattern of attacks, the Cyber Protect team is urging heightened vigilance across all schools, not just those already affected. Staff are encouraged to log into their payroll accounts and take the following steps as soon as possible:
- Set up two-step verification, so a password alone isn't enough to gain access. See our guide to multi-factor authentication for more on why this matters and how to enable it.
- Change to a long, strong, unique password for the payroll account — one not reused anywhere else. Our World Password Day article has practical tips on building stronger passwords.
- Enable passkeys, where the payroll provider supports them, as a stronger alternative to passwords. Read more on the role of passkeys in cyber resilience and cyber security.
- Check that banking and contact details are correct and up to date, so any unauthorised change is easier to spot.
This type of attack is a form of social engineering and account takeover fraud. For more background on how these scams operate and how to spot the warning signs, see our articles on social engineering, impersonation and fraud and what to do if you suspect a financial scam.
Further Support Available
The Cyber Protect team has produced free guidance on setting up two-step verification, creating strong passwords, and using passkeys, available through their Police CyberCheck tool at cybercheck.southeastcyber.police.uk (or simply type "CyberCheck.info" into a browser).
Schools can also access fully-funded cyber security training delivered by the Cyber Protect team, covering:
- Senior Leadership and Governors sessions
- Staff cyber security awareness training
- Pupil-focused inputs
More details are available at southeastcyber.police.uk/education.
Advisory based on guidance issued by Claire Walden, Cyber Protect Officer, South East Cyber Crime Unit.
