Bromcom (UK school software): intruder took email addresses and sign-in details from a superseded single sign-on registration service still running for an internal system; school MIS not affected
UK education software provider Bromcom has notified customers of a personal data breach involving legacy single sign-on (SSO) registration functionality in its Communication Server environment, The Register reported on 6 October 2026. In a 24 September post on the EduGeek forum, a Bromcom account said an unauthorised third party had accessed and retrieved email addresses and limited information tied to affected SSO registrations. Bromcom identified the incident on 6 September after reports of SSO access problems. The service held email addresses linked to SSO registrations, the sign-in provider used (such as Microsoft or Google), registration and last sign-in dates where recorded, and internal user and registration reference numbers; Bromcom says it held no passwords or authentication tokens and did not allow access to Microsoft or Google accounts. The superseded component had stayed in production because an internal system still called it, and has now been withdrawn. Bromcom says it found no evidence its school Management Information System (MIS), which holds student, attendance and behaviour data, was compromised, and it is working with forensic specialists and liaising with schools, trusts and the authorities. Bromcom software is used by more than 5,000 schools and 390 multi-academy trusts. Primary: The Register (Bromcom statement and FAQ); switch primary when a public Bromcom notice is available.
- Product
- Bromcom Communication Server legacy SSO registration service
- Versions
- n/a — incident; legacy component withdrawn
- Exploited in Australia?
- unknown
- Patch to
- Schools and trusts using Bromcom: expect targeted phishing that quotes the SSO provider or sign-in dates, and remind staff and parents not to approve unexpected Microsoft or Google sign-in prompts. Everyone: inventory superseded authentication and registration endpoints, find what still calls them, and switch them off once callers are migrated rather than leaving them reachable.
