The incident, understood to have occurred last week, involved 607,000 records.
The data taken includes names, job titles, telephone numbers and email addresses of government officials, school leaders and university staff, but does not include bank details or other sensitive information.
The DfE confirmed the incident and said it is working closely with the National Cyber Security Centre and the National Crime Agency (NCA).
It said the breach was quickly contained and that the data protection risk to individuals is not high.
The department’s help desk self-service portal and its Turing Scheme portal – used by education providers to manage funding for international placements – were attacked, and it has switched to using the telephone while work to fix them is carried out.
The DfE has reported the incident to the Information Commissioner’s Office.
A spokesperson said: “We have robust processes in place to protect information and took swift action to contain this incident.
“The information involved is limited to customer service contact details relating to individuals and organisations.
“No other data has been accessed.
“We continue to work closely with the National Cyber Security Centre and the National Crime Agency.”
Paul Whiteman, general secretary of school leaders’ union NAHT, said: “These reports are concerning.
“While school leaders’ names and email addresses will largely be in the public domain anyway, the DfE needs to act quickly to reassure people by clarifying exactly what information has been accessed and that it goes no further.
“Cyber leaks can have serious consequences and so it will be incumbent on the department to get to the bottom of what has happened and reassure the sector that steps have been taken to prevent any recurrence.”

Politics Editor