As we head into Cybersecurity Awareness Month, school and multi-academy trust (MAT) leaders are facing a growing range of cyber threats, including increasingly sophisticated social engineering attacks. While email phishing is still a concern, it is no longer the only way criminals try to gain access to school systems or information.
Email security has become much better at spotting and blocking suspicious messages, so attackers are increasingly using other channels. These include QR code deception (quishing), malicious text messaging (smishing), and direct telephone or voice-cloning fraud (vishing).
For Executive Principals, Trust CEOs, Chief Financial Officers, School Business Managers (SBMs), and Headteachers, this creates a significant operational risk. These scams rely on staff being busy, acting quickly and trusting communications that appear genuine at first glance – all of which are common in the fast-paced environment of school and trust administration.
What are the most common social engineering attacks against schools?
These newer types of attacks are designed to get around the security controls schools already have in place by shifting interaction away from enterprise-managed laptops and onto personal mobile phones or direct phone calls.
Quishing, or QR code phishing, uses fake QR codes placed on things that look completely routine, such as posters, supplier delivery notes or PDF invoices. They may appear to link to a survey, document portal or other legitimate service. When someone scans the code with their phone, they can be taken directly to a fake website designed to steal their login details. Because the activity takes place on a mobile device, some of the security checks used on school computers may not apply.
Smishing works in a similar way, but uses text messages. Staff might receive a message that appears to come from an organisation they recognise, such as the Department for Education (DfE), HM Revenue & Customs (HMRC) or a pension provider. The message may create a sense of urgency by mentioning salaries, tax or pension changes, encouraging the recipient to click a link and enter their details.
Vishing is becoming a particular concern for school and trust finance teams, especially as criminals can now use generative AI to create convincing copies of someone’s voice. Using low-cost AI tools trained on publicly available media audio, such as school assembly videos or trust webinars, cybercriminals can replicate the distinct voice of a Trust CEO, Headteacher, or local authority official with chilling accuracy. Attackers execute targeted phone calls to school business managers or finance administrators, creating high-pressure scenarios that demand immediate out-of-band invoice approvals, bank detail modifications, or emergency BACS transfers.
These scams can be particularly effective in education because finance teams often work to tight payment deadlines and rely on established relationships and trust between colleagues. A request that appears to come directly from a senior leader can therefore feel genuine, particularly when staff are under pressure to act quickly.
The DfE’s Digital and Technology Standards expect organisations to have appropriate security measures in place, including robust identity verification, access controls, and multi-factor authentication (MFA) across all administrative tools. A stolen username and password – obtained through a fake QR code, text message or other scam – could give an attacker access to wider school or trust systems. If this leads to sensitive information being compromised, the organisation may also have data protection responsibilities, including potentially reporting the breach to the Information Commissioner’s Office (ICO).
Furthermore, executing unauthorised financial transfers as a result of a vishing scam represents a direct breakdown in internal financial controls, placing the trust in conflict with the statutory governance obligations set out in the Academy Trust Handbook.
How to safeguarding against social engineering in schools?
Protecting schools and trusts from these scams requires a combination of clear procedures, staff awareness and appropriate technology.
For finance and administration teams, one of the most important safeguards is independent verification. Any request to change a supplier’s bank details, make an emergency payment or bypass standard sign-off procedures received via phone, text, or email must be checked using a trusted contact method before anything is changed or paid. For example, if someone phones or emails asking for a supplier’s bank details to be updated, staff should use a known telephone number already held on the organisation’s records to confirm the request, rather than using a number provided in the message or by the caller.
IT teams also have an important role to play. School-issued mobile devices should have appropriate security and web protection in place, just as school computers do. Schools should also check that their web filtering and security systems provide protection when staff use mobile devices to scan QR codes or open links while connected to the school’s network.
How One Education can help
As social engineering attacks become more sophisticated, school and trust leaders need to act now to strengthen security across every channel staff use to communicate and make decisions.
One Education bridges this operational gap through our dedicated Strategy & Assurance Discovery Framework. Our specialist team works directly alongside Headteachers, CEOs, CFOs, SBMs, and Designated Safeguarding Leads (DSLs) to identify weaknesses across the different ways staff communicate, including email, mobile phones and voice calls.
We review existing internal financial controls to eliminate single points of failure, assist leadership teams in drafting comprehensive Acceptable Use Policies (AUPs), and deliver modern, scenario-based cyber awareness training that equips staff to identify non-email threats effectively.
Protecting your institution’s financial integrity, administrative credentials, and public reputation requires securing every communication channel. Contact the One Education IT Services team today to arrange a comprehensive Cyber Risk Audit or Assurance Review.

