Incident
Published 2026-06-08
Verified 2026-09-19

UWA Callista student system: credentials exposed, unauthorised access on 28 May

The University of Western Australia's own notice says that on 28 May 2026, UWA IT identified unauthorised external access to Callista, the university's Student Information Management System, after system access credentials were unintentionally exposed online. UWA says it secured the system and removed the vulnerability. Exposed fields, on that notice, include name, UWA student ID, UWA staff ID if applicable, home and mobile numbers, date of birth (day and month only), personal email, postcode, and enrolment status as at 2 April 2026, for some prospective students, current students and recent graduates. UWA says financial details were not involved, that it found no evidence of malicious use, and that it emailed affected people on 8 June 2026. UWA password resets were not required. ASD's ACSC had not published a matching alert at last check.

Exploited in Australia?
unknown

Primary: UWA Callista notice ยท Vendor: UWA (institution)

breaches australia