Per The Register. UK education software provider Bromcom alerted its customers to a personal data breach impacting its single sign-on (SSO) technology, potentially exposing email addresses and other limited information.
The incident occurred within Bromcom's Communication Server environment, specifically affecting a legacy SSO registration functionality. An unauthorized third party gained access to and retrieved email addresses associated with SSO registrations, along with registration and last sign-in dates where recorded, and internal user and registration reference numbers. Bromcom stated that its school Management Information System (MIS), which handles sensitive student data, was not compromised, and that account passwords or authentication tokens were not accessed. The company identified the breach on Sept. 6 after reports of SSO access issues and has since removed the affected legacy functionality. Bromcom is collaborating with external forensic specialists to fully assess the scope of the breach and is working with relevant schools and authorities.
Source: The Register
