Bromcom breach exposes data via legacy SSO service
UK school software provider Bromcom notified customers of a data breach involving its legacy single sign-on registration functionality. Intruders retrieved email addresses and limited registration data; the school MIS was not compromised.
- Incident identified on September 6 after reports of SSO access issues
- Breach exposed emails, registration dates and internal user reference numbers
- No passwords or authentication tokens were stored in the affected component
- Bromcom software is used by over 5,000 schools and 390 multi-academy trusts
Read next
Security