Forgotten Login Service Exposes User Data at School Software Provider Bromcom
Bromcom, a UK provider of school management software, has told customers about a personal data breach affecting its single sign-on (SSO) technology. In a post on the EduGeek forum dated September 24, the company said an unauthorised third party accessed and retrieved email addresses and limited information tied to affected SSO registrations. The company says it identified the incident on September 6 after reports of SSO access problems, and it has since withdrawn the legacy functionality from production.
The affected component was legacy SSO registration functionality in Bromcom's Communication Server environment. It held email addresses, the identity provider used (such as Microsoft or Google), registration and last sign-in dates where recorded, and internal user and registration reference numbers. Bromcom said it did not hold account passwords or authentication tokens, and that the incident did not give access to Microsoft or Google accounts. The company also said it found no evidence that its school Management Information System, which handles student data, attendance, behaviour and administration, was compromised. External forensic specialists are working to determine the nature and scope of the data involved.
The old functionality had stayed in production after being superseded because, in the supplier's words, "it was still being called by an internal system." Bromcom's software is used by more than 5,000 schools and 390 multi-academy trusts. The Register has asked the company for further comment.