PunchEight-year-old dies, others injured in Anambra auto crashThe Jerusalem PostJewish settler extremists torch Palestinian homes, livestock shelters in West Bank attack - reportBollywood HungamaSunny Leone-Rahul Dev’s Chudail lands in rights ROW; Ganesh Jain issues public notice claiming exclusive digital, TV and allied rightsInquirerSara Duterte to NBI: Make public Gracioso’s lie detector test videoDaily MaverickSHARE WITH US: Online schools in South Africa: what should parents know?UOLSe a IA responde tão rápido, o que a escola ainda precisa ensinar?ХабрОкно в свет: почему Windows названа Windows, а иконки — иконкамиZDF heuteEntdecken Sie das ZDF-NachrichtenstudioThe Straits TimesResale flat transactions with ‘greater complexity’ should be handled by private lawyers: HDBعالم التقنيةسلسلة تلفزيونات Redmi TV X RGB Mini LED تغير قواعد الألعاب والترفيهCapital FMKICD begins distributing Grade 11 textbooks ahead of 2027 Senior School transitionVilaWebFrancis Halzen, Nobel de física per convertir el gel del Pol Sud en una finestra a l’univers
The Daily Newsstand · Free, Always
Tuesday, October 6, 2026

Legacy sign-on service comes back to bite school software provider Bromcom

Translate

Intruders retrieved email addresses from superseded tech kept running for an internal system

UK education software provider Bromcom has notified customers of a personal data breach affecting its single sign-on (SSO) technology.

In a September 24 EduGeek post, an account named Bromcom_Alastair said an unauthorized third party had accessed and retrieved email addresses and limited information associated with affected SSO registrations.

The incident involved legacy SSO registration functionality in Bromcom's Communication Server environment. The company confirmed in an FAQ it found no evidence that its school Management Information System (MIS), used to manage student data, attendance, behaviour, and administration, was compromised.

REG AD

Bromcom said it was working with external forensic specialists to determine the nature and scope of the data involved.

REG AD

The company identified the incident on September 6 after reports of SSO access problems and has since withdrawn the legacy functionality from production.

The service held email addresses associated with SSO registrations, the provider used, such as Microsoft or Google, registration and last sign-in dates where recorded, and internal user and registration reference numbers.

Bromcom said the affected component did not hold account passwords or authentication tokens.

The legacy SSO registration functionality had remained in production after being superseded because "it was still being called by an internal system," the supplier said. 

The incident did not enable access to Microsoft or Google accounts, whose authentication services are separate from the affected component said Bromcom.

The Register has asked Bromcom to comment further.

Bromcom provides information management software used in schools and the wider education sector in the UK. It offers tools for budgeting, timetabling, HR, and benchmarking.

Bromcom's software is used by more than 5,000 schools and 390 multi-academy trusts (organizations that run multiple schools). Recent customer wins include Newport City Council, the Ministry of Defence, Warwickshire County Council, and the Northern Ireland Education Authority. ®

REG AD

Updated to add at 0834 UTC, October 6

A spokesperson for Bromcom said: "We recently identified, contained and began investigating an IT incident. Our investigation is ongoing to determine the nature and scope of any data involved, and we have already taken steps to resolve any disruption. We are liaising with the relevant schools and trusts, as well as the appropriate authorities."

View the original on The Register →

KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.