Bromcom notifies schools of data breach affecting legacy single sign-on system

No evidence that school management system compromised, says supplier

By LineZotpaper
Published
Read Time2 min
UK education software provider Bromcom has notified schools of a personal data breach affecting its legacy single sign-on (SSO) registration functionality, after an unauthorized third party accessed email addresses and related registration data.

Bromcom, a provider of information management software used in more than 5,000 schools and 390 multi-academy trusts across the UK, disclosed the incident in a September 24 post on the EduGeek forum. The company said an unauthorized third party had accessed and retrieved email addresses and limited information associated with affected SSO registrations.

The breach involved legacy SSO registration functionality in Bromcom's Communication Server environment. Bromcom stated in an FAQ that it found no evidence that its school Management Information System (MIS), used to manage student data, attendance, behaviour, and administration, was compromised.

The company identified the incident on September 6 after reports of SSO access problems and has since withdrawn the legacy functionality from production. The affected component held email addresses, the SSO provider used (such as Microsoft or Google), registration and last sign-in dates where recorded, and internal user and registration reference numbers. Bromcom said the component did not hold account passwords or authentication tokens, and the incident did not enable access to Microsoft or Google accounts.

Bromcom explained that the legacy SSO registration functionality had remained in production after being superseded because "it was still being called by an internal system." The company is working with external forensic specialists to determine the nature and scope of the data involved.

Recent customer wins for Bromcom include Newport City Council, the Ministry of Defence, Warwickshire County Council, and the Northern Ireland Education Authority.

§

Analysis

Why This Matters

  • Schools hold sensitive personal data on students and staff; a breach of email addresses could enable targeted phishing attacks.
  • The incident highlights risks of maintaining legacy systems that remain in production beyond their intended lifespan.
  • As a widely used education software provider, the breach may affect a large number of UK schools and trusts.

Background

Bromcom is a major supplier of management information systems to UK schools and multi-academy trusts, offering tools for budgeting, timetabling, HR, and benchmarking. Legacy components sometimes remain in production due to integration dependencies, but they can become security vulnerabilities if not properly isolated or decommissioned.

Key Perspectives

Affected Schools: Concerned about the exposure of staff email addresses and possible follow-on attacks, while reassured that the core MIS and student data were not accessed. Bromcom: Has taken the affected functionality offline, engaged forensic specialists, and stated that no passwords or authentication tokens were compromised. The company emphasises that the breach did not extend to connected Microsoft or Google accounts. Critics and Security Experts: May question why a legacy SSO component was left in production after being superseded, and whether adequate vulnerability assessments were in place.

What to Watch

  • Findings from the external forensic investigation into the scope of the breach.
  • Any regulatory action by the UK Information Commissioner's Office (ICO) under data protection law.
  • Potential future disclosures from Bromcom about remediation and steps to prevent similar incidents.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.