Legacy sign-on service comes back to bite school software provider Bromcom
Intruders retrieved email addresses from superseded tech kept running for an internal system
UK education software firm Bromcom has informed its customers of a personal data breach affecting its single sign-on (SSO) technology. The breach, discovered on September 6, involved unauthorized access to email addresses and limited information linked to SSO registrations in Bromcom's Communication Server environment. The company's FAQ stated no evidence of compromise to its school Management Information System (MIS), which manages student data, attendance, behavior, and administration.
Bromcom identified the issue and removed the legacy SSO registration functionality from production the same day. The compromised component did not store account passwords or authentication tokens. Bromcom confirmed the affected service held email addresses associated with SSO registrations, such as Microsoft or Google, registration and last sign-in dates, and internal user and registration reference numbers.
The legacy SSO registration functionality, still being called by an internal system, had remained in production after being replaced. Bromcom's software is used by over 5,000 schools and 390 multi-academy trusts in the UK. The company stated its investigation was ongoing and liaising with affected schools, trusts, and relevant authorities.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.