A new report reveals that over half of school-related data breaches come from students seeking dares, clout, or revenge — and the consequences could be far-reaching.
Students Behind Most School Cyber Breaches, Says ICO
In a startling revelation, the UK Information Commissioner’s Office (ICO) reports that students were responsible for 57% of internal data breaches in schools, raising serious alarms about youth cybersecurity behavior and institutional vulnerabilities.
- The ICO reviewed 215 breach reports tied to in-school security incidents.
- These breaches often stemmed from simple tactics — like guessing weak passwords or discovering credentials written down or left unsecured.
“Children are hacking into their schools’ computer systems — and it may set them up for a life of cyber crime,” the report warns.
Dares, Revenge, and Recognition Fuel the Trend
The motivations behind these student-led breaches range from curiosity to more concerning drivers:
- Dares and challenges among peers
- Desire for notoriety within student communities or online forums
- Revenge or rivalry within the school environment
- In some cases, even financial incentives or recruitment into broader hacking forums
The ICO gave the example of three Year 11 students who used hacking tools to infiltrate a school’s student information system, bypassing both password protections and security protocols. Two of the students admitted to being active in online hacking forums.
“What starts out as a dare… can ultimately lead to damaging attacks,” said Heather Toomey, principal cyber specialist at the ICO.
School Security Weaknesses Make It Easier
The report doesn’t place all the blame on students. It reveals systemic lapses in school cybersecurity practices that often make these breaches possible.
Key findings include:
- 23% of breaches occurred due to weak data handling, such as students using teacher devices.
- 20% were linked to staff using personal devices for school work.
- 17% stemmed from improper access controls on systems like Microsoft SharePoint.
- Lack of GDPR training and awareness among school staff compounded the risks.
In many cases, students didn’t need advanced skills — just basic digital literacy and opportunity.
From Mischief to Criminal Pathways
While some students may see hacking as harmless fun or a technical challenge, the ICO warns that early exposure to cyber offenses can normalize illicit digital behavior.
- These incidents may escalate into attacks on larger organizations or critical infrastructure if left unchecked.
- The ICO emphasized that children engaging in such activities are at risk of entering the cybercrime ecosystem.
This trend is part of a broader challenge facing regulators worldwide: how to balance early tech curiosity with strong ethical and legal boundaries.
ICO Urges Schools to Act
Calling its findings “worrying,” the ICO issued strong recommendations for schools to raise defenses and awareness:
- Refresh GDPR and cybersecurity training for staff
- Enforce stronger access controls and authentication
- Stop the use of personal devices for sensitive data access
- Promote responsible digital citizenship among students
- Report data breaches on time, per regulatory requirements
The agency urges educators to proactively engage with students who demonstrate hacking tendencies — ideally redirecting them into constructive cybersecurity learning paths rather than punitive measures.








