OVIC finds Victoria's Department of Education breached privacy law: a school left a server unpatched after the 27 October 2025 ASD critical alert, and attackers copied names, school emails and encrypted passwords of every government school student plus hundreds of thousands of former students
The Office of the Victorian Information Commissioner (OVIC) has published its investigation into the student data breach the Department of Education reported on 7 January 2026, and found the department contravened Information Privacy Principles 4.1 (security) and 4.2 (destroying data no longer needed). The Australian Signals Directorate issued a critical alert at 10am on 27 October 2025; the department passed it to school technicians the same afternoon, but not every school patched, and the department had no way of checking that they did. Attackers got in through one school's internet-facing server on or before 6 November 2025. A vendor detected the activity on 2 December, forensic work confirmed data had left on 23 December, and media reporting began on 14 January. The stolen database held every government school student's first name and surname, school, year level, school email address and encrypted password, and the same details for hundreds of thousands of former students, which the department kept so email addresses would not be reissued. OVIC called that retention disproportionate. It also found the department's vulnerability scanning did not cover every school and that critical findings were not always fixed. OVIC saw no evidence of misuse soon after the attack but notes the copy could be used later, a particular worry for families escaping violence or under protection orders. OVIC made seven recommendations due by 31 December 2026, including a plan to align with the Essential Eight. The department has accepted them, promised an archive policy for old student records by December and an internal audit in 2027, and plans centrally provided vulnerability management for schools by the end of 2028. OVIC's report does not name the vulnerability. Primary: OVIC investigation report; wire: iTnews (7 Oct).
- Product
- Victorian Department of Education student database (government schools)
- Versions
- n/a — incident
- Exploited in Australia?
- unknown
- Patch to
- Families: expect phishing that quotes a child's school or year level; current school passwords were reset in January. Schools, councils and agencies with devolved IT: when a critical ASD or ACSC alert lands, track every site to confirmation that the patch is in, not just that the notice was sent; cover every internet-facing server with vulnerability scanning; delete or archive old account records instead of keeping them in live systems. Practitioner page: /knowledge/essential-eight.
Primary: OVIC — Investigation into the data breach of student information held by the Department of Education (report, October 2026, PDF) · iTnews — Unpatched server behind Vic student data breach (7 Oct 2026)
