The Scottish Qualifications Authority has confirmed to DIGIT that they are investigating a cyber-incident after more than 17,000 files related to the organisation were made available on a dark web forum on Saturday, March 8 at 3.20pm.
The forum post, which was initially discovered and highlighted to DIGIT by a local security researcher, purported to contain coursework and assignments for the 2024/25 academic year, as well as other historic documents belonging to the organisation.
While the exact cause of the breach has not been confirmed (at time of writing), the SQA issued a statement to DIGIT, saying: “SQA can confirm that the issue relates to the unauthorised use of website-access credentials at a single SQA centre and is not the result of a cyber-attack.
“The centre’s access to SQA Secure has been suspended. Other SQA centres can continue to safely access SQA Secure while our investigations continue.”
The national accreditation and awarding body, SQA, is responsible for national qualifications, including Highers and Advanced Highers – they all also play a huge role in curriculum development and examination.
Over the weekend, a post titled ‘Scottish Qualifications Authority – 2004-2025 Assignment QPs & Resources’, from a user called ‘pine’, appeared on a dark web forum.
The dataset allegedly contains 17,460 files, with the post stating that ‘this leak contains the current 2025 coursework/assignments.
Recommended reading
- As-a-Service Platforms Drive Four-fold Ransomware Increase
- UK Proposes Ban on Public Sector Ransomware Payments
- Ransomware Payouts Plummet by £350M in 2024
‘These documents are taken from secure.sqa.org.uk which they describe as containing “assessments and support materials for teachers, lecturers and training practitioners delivering SQA qualifications.”
‘Note: A small portion of the documents, mostly the much older ones, are probably available through their main site somewhere’.
Educational bodies, such as the SQA, handle vast amounts of sensitive and confidential data, making them a potentially lucrative target for cyber-attacks – this has especially been the case since the transition to more remote-based learning following the pandemic.





