Bromcom, a provider of information management software used in more than 5,000 schools and 390 multi-academy trusts across the UK, disclosed the incident in a September 24 post on the EduGeek forum. The company said an unauthorized third party had accessed and retrieved email addresses and limited information associated with affected SSO registrations.
The breach involved legacy SSO registration functionality in Bromcom's Communication Server environment. Bromcom stated in an FAQ that it found no evidence that its school Management Information System (MIS), used to manage student data, attendance, behaviour, and administration, was compromised.
The company identified the incident on September 6 after reports of SSO access problems and has since withdrawn the legacy functionality from production. The affected component held email addresses, the SSO provider used (such as Microsoft or Google), registration and last sign-in dates where recorded, and internal user and registration reference numbers. Bromcom said the component did not hold account passwords or authentication tokens, and the incident did not enable access to Microsoft or Google accounts.
Bromcom explained that the legacy SSO registration functionality had remained in production after being superseded because "it was still being called by an internal system." The company is working with external forensic specialists to determine the nature and scope of the data involved.
Recent customer wins for Bromcom include Newport City Council, the Ministry of Defence, Warwickshire County Council, and the Northern Ireland Education Authority.