Legacy sign-on service comes back to bite school software provider Bromcom
Intruders retrieved email addresses from superseded tech kept running for an internal system
UK education software provider Bromcom has informed its customers about a personal data breach affecting its single sign-on (SSO) technology. The incident, discovered on September 6, involved unauthorized access to email addresses and limited information associated with compromised SSO registrations within the company's legacy SSO registration functionality.
Bromcom has since withdrawn the legacy functionality from production and is collaborating with external forensic specialists to determine the full extent of the data breach. The affected component did not contain account passwords or authentication tokens, and the incident did not permit access to external accounts like Microsoft or Google.
Bromcom, which operates software used in over 5,000 schools and 390 multi-academy trusts in the UK, stated that the compromised service held email addresses associated with SSO registrations, the registration and last sign-in dates, and internal user and registration reference numbers. The company acknowledged that the legacy SSO registration functionality had remained in production due to continued use by an internal system. Bromcom has sought comment from the affected parties.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.