Security News

Delayed Patch at One School Led to Victorian Student Data Breach, Regulator Finds

iTnews · 7 Oct 2026
Key Takeaway Patch critical vulnerabilities as soon as an alert arrives, check that every site or office has actually done it, and delete old customer or user data you no longer need.

A major Victorian Education data breach was caused by a school that delayed patching a critical server vulnerability, along with weaknesses in central oversight, according to an investigation by the Office of the Victorian Information Commissioner (OVIC). Unknown attackers exploited the flaw to access and copy a database of current and former students. The breach happened around early November 2025, but data theft was not confirmed until just before Christmas, which led to a mass password reset ahead of the school year.

OVIC found the school had not applied the fix despite a directive from the department. That directive was based on an Australian Signals Directorate alert issued on 27 October 2025, and schools were told about the vulnerability and how to patch it on the same day. OVIC said "not all schools followed the advice", and that even after the breach was confirmed, the department struggled to get schools to act on how critical the patch was.

The department was also criticised. Its vulnerability management program does not cover all schools, and not all critical issues found in covered schools were fixed. OVIC said guidance on preparing for a major cyber incident was insufficient. It also criticised the department for keeping credentials of many former students in the same database, a disproportionate response to avoiding duplicate email addresses. The department says it has since deployed additional threat discovery tools.

Summarised by CISO AI from iTnews, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.