VYPR
breachPublished Oct 5, 2026· 1 source

Bromcom Breach Exposes Student Data via Legacy SSO Flaw

UK education software provider Bromcom has suffered a data breach, with attackers accessing email addresses and associated details through a vulnerability in its legacy single sign-on system.

UK education software provider Bromcom has alerted its customers to a personal data breach that originated from a vulnerability within its single sign-on (SSO) technology. The incident, discovered on September 6, involved unauthorized access to and exfiltration of email addresses and other limited information linked to SSO registrations within Bromcom's Communication Server environment.

In a post on the EduGeek forum dated September 24, a Bromcom representative detailed that the breach specifically targeted legacy SSO registration functionality. The compromised data includes email addresses, the identity provider used (such as Microsoft or Google), registration and last sign-in dates where available, and internal reference numbers for users and registrations. Crucially, Bromcom has stated that account passwords and authentication tokens were not exposed, and its core student management system, known as the Management Information System (MIS), remained secure and unaffected.

The company is actively collaborating with external forensic specialists to thoroughly investigate the nature and full scope of the breach. Following the discovery, Bromcom moved swiftly to remove the compromised legacy SSO functionality from its production environment. This legacy component had remained in place because an internal system continued to call it, despite being superseded by newer systems.

Bromcom emphasized that the compromised component is separate from the authentication services provided by Microsoft or Google, meaning that direct access to users' Microsoft or Google accounts was not facilitated by this breach. The company's MIS system, which handles sensitive student data including attendance, behavior, and administrative records, was also confirmed to be secure.

Bromcom is a significant provider of information management software within the UK's education sector. Its suite of tools supports various administrative functions, including budgeting, timetabling, HR, and benchmarking. The company serves a substantial user base, with its software utilized by over 5,000 schools and 390 multi-academy trusts across the country.

The incident highlights the persistent risks associated with maintaining legacy systems, even those seemingly superseded. The continued reliance on older code, even for internal processes, can create unforeseen attack vectors. The breach underscores the importance of comprehensive system audits and timely decommissioning of outdated components to prevent such security incidents.

While the core student data systems were not breached, the exposure of email addresses and associated metadata could still pose risks to affected individuals and institutions. These details could potentially be used in targeted phishing campaigns or other social engineering attacks aimed at gaining further access.

Synthesized by Vypr AI