West Lothian schools cyber attack
Early on Tuesday 6 May 2025, West Lothian Council’s education network suffered a suspected ransomware attack. Teachers were told to disconnect devices, and an investigation began involving Police Scotland and the Scottish Government.
Officials initially reported no evidence of data theft or compromise of the council’s corporate systems. By late May, however, the council confirmed that a small percentage of education network data, some of it personal and sensitive, had been stolen. The leaked files included correspondence and identification documents such as driving licences. Pupil records, financial details and social work reports were stored elsewhere and were not affected.
Who was affected
The education network covers 143 sites: 13 secondary schools, 69 primary schools and 61 nurseries. A subset of schools, including Armadale Academy, Bathgate Academy, Broxburn Academy, Inveralmond, Linlithgow Academy, St Kentigern’s and West Calder High, were confirmed to have had data compromised, including that of staff, parents and possibly pupils.
The council’s response
- Network isolation: the compromised education network was sealed off from the rest of the council’s systems.
- Contingency plans: all schools stayed open and SQA exams were unaffected.
- Prompt notification: families received emails urging vigilance against phishing and recommending password changes.
- Targeted follow-up: those whose data was most sensitive were contacted directly and offered support.
With Police Scotland and the Scottish Government involved, the attack remains a live criminal investigation. The ransomware group Interlock later claimed responsibility.
Key lessons
- Schools are high-value targets. As recent retail attacks show, ransomware groups go after organisations that hold sensitive data and cannot tolerate downtime.
- Network segmentation works. Isolating the education network prevented wider council disruption.
- Preparedness pays. Existing contingency plans kept teaching and exams on track.
- Transparent communication builds trust. Parents and staff were informed promptly without causing panic.
- Data classification matters. Keeping pupil, social work and financial records separate limited the impact of the leak.
- Vigilance continues after the incident. Phishing that exploits stolen data often follows a breach.
While distressing, the attack is a strong case study in incident preparedness, network segregation and crisis communication. It should also be a wake-up call for educational networks across the UK to invest further in cyber defences, staff training and incident response planning.