{
  "id": 12350068,
  "title": "Legacy sign-on service comes back to bite school software provider Bromcom",
  "url": "https://urgent.news/2026/10/06/legacy-sign-on-service-comes-back-to-bite-school-software-provider-12350068",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-06T09:30:00.000Z",
  "source": {
    "name": "The Register",
    "slug": "the-register",
    "url": "https://www.theregister.com/security/2026/10/06/legacy-sign-on-service-comes-back-to-bite-school-software-provider-bromcom/5301156"
  },
  "original_language": "en",
  "account": "Education software firm Bromcom has announced a personal data breach involving its legacy single sign-on (SSO) system. According to an EduGeek post dated September 24, an unauthorized third party gained access to email addresses and limited information associated with SSO registrations. The affected component, part of Bromcom's Communication Server environment, held email addresses linked to SSO registrations, such as those from Microsoft or Google, registration and last sign-in dates, and internal user and registration reference numbers. Importantly, Bromcom stated that the compromised component did not contain account passwords or authentication tokens. The incident occurred on September 6 after customers reported issues with SSO access. Bromcom promptly withdrew the legacy functionality from production and has since been working with external forensic specialists to assess the full extent of the breach. The company confirmed that its school Management Information System, which manages student data, attendance, behavior, and administration, remained unaffected. Bromcom, a provider of information management software for schools across the UK, serves over 5,000 schools and 390 multi-academy trusts. Recent customers include Newport City Council, the Ministry of Defence, Warwickshire County Council, and the Northern Ireland Education Authority. The company has taken steps to resolve any disruption and is in contact with affected schools and authorities while investigating the incident further.",
  "summary": "Intruders retrieved email addresses from superseded tech kept running for an internal system",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register Science",
        "title": "Legacy sign-on service comes back to bite school software provider Bromcom",
        "url": "https://urgent.news/2026/10/06/legacy-sign-on-service-comes-back-to-bite-school-software-provider",
        "published": "2026-10-06T09:30:00.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}