Breach, Privacy

Bromcom notifies customers of personal data breach affecting SSO technology

(Adobe Stock)

According to The Register, UK education software provider Bromcom has alerted its customers to a personal data breach impacting its single sign-on (SSO) technology. The incident involved unauthorized access to email addresses and other limited information associated with SSO registrations.

The breach occurred within Bromcom's Communication Server environment, specifically affecting a legacy SSO registration functionality. While the company confirmed that its school Management Information System (MIS) was not compromised, the incident resulted in the retrieval of email addresses, registration details from providers like Microsoft or Google, and internal user reference numbers. Bromcom stated that account passwords and authentication tokens were not accessed. The company identified the issue on Sept. 6 after reports of SSO access problems and has since removed the affected legacy functionality. Bromcom is collaborating with forensic specialists to ascertain the full scope of the breach. This incident highlights the ongoing security challenges faced by educational technology providers, even when core student data systems remain intact.

Source: The Register

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds