Security News

Forgotten Login Service Exposes User Data at School Software Provider Bromcom

The Register · 5 Oct 2026
Key Takeaway Regularly review your systems for old or superseded services that are still running, and either retire them properly or secure them, because forgotten components can become an easy way in for attackers.

Bromcom, a UK provider of school management software, has told customers about a personal data breach affecting its single sign-on (SSO) technology. In a post on the EduGeek forum dated September 24, the company said an unauthorised third party accessed and retrieved email addresses and limited information tied to affected SSO registrations. The company says it identified the incident on September 6 after reports of SSO access problems, and it has since withdrawn the legacy functionality from production.

The affected component was legacy SSO registration functionality in Bromcom's Communication Server environment. It held email addresses, the identity provider used (such as Microsoft or Google), registration and last sign-in dates where recorded, and internal user and registration reference numbers. Bromcom said it did not hold account passwords or authentication tokens, and that the incident did not give access to Microsoft or Google accounts. The company also said it found no evidence that its school Management Information System, which handles student data, attendance, behaviour and administration, was compromised. External forensic specialists are working to determine the nature and scope of the data involved.

The old functionality had stayed in production after being superseded because, in the supplier's words, "it was still being called by an internal system." Bromcom's software is used by more than 5,000 schools and 390 multi-academy trusts. The Register has asked the company for further comment.

data breach single sign-on legacy systems education sector

Summarised by CISO AI from The Register, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.