Ethical Hacking News
Bromcom, a software provider for schools and education institutions in the UK, has disclosed a data breach that has left thousands of schools vulnerable to cyber threats. The breach, which occurred in September 2026, involved the unauthorized access of email addresses associated with Single Sign-On (SSO) registrations. The incident has raised concerns about the security of Bromcom's software and highlights the need for education institutions to prioritize their cybersecurity and keep their software up-to-date.
Bromcom, a leading software provider for schools and education institutions in the UK, has disclosed a data breach that left thousands of schools vulnerable to cyber threats. The breach occurred in September 2026 due to the legacy SSO registration functionality in Bromcom's Communication Server environment. The affected component stored email addresses, registration, and last sign-in dates, but not account passwords or authentication tokens. The breach has raised concerns about the security of Bromcom's software, used by 5,000 schools and 390 multi-academy trusts in the UK. Bromcom has withdrawn the legacy functionality from production and is working with external forensic specialists to address the breach. The incident highlights the need for education institutions to prioritize their cybersecurity and keep their software up-to-date.
Bromcom, a leading software provider for schools and education institutions in the United Kingdom, has recently disclosed a data breach that has left thousands of schools vulnerable to cyber threats. The breach, which occurred in September 2026, involved the unauthorized access of email addresses associated with Single Sign-On (SSO) registrations, according to a post by Bromcom_Alastair on EduGeek.
The incident was attributed to the legacy SSO registration functionality in Bromcom's Communication Server environment, which had remained in production after being superseded by newer technology. The affected component did not hold account passwords or authentication tokens, but it did store email addresses, registration and last sign-in dates, and internal user and registration reference numbers.
The breach was discovered by Bromcom after reports of SSO access problems, and the company subsequently withdrew the legacy functionality from production. Bromcom has confirmed that the incident did not enable access to Microsoft or Google accounts, whose authentication services are separate from the affected component.
The breach has raised concerns about the security of Bromcom's software, which is used by over 5,000 schools and 390 multi-academy trusts in the UK. The incident highlights the need for education institutions to prioritize their cybersecurity and keep their software up-to-date.
Bromcom has taken steps to address the breach, including working with external forensic specialists to determine the nature and scope of the data involved. The company has also withdrawn the legacy functionality from production to prevent further unauthorized access.
The breach is a reminder of the importance of cybersecurity and the need for education institutions to be vigilant in protecting their data. It is also a cautionary tale about the risks associated with legacy technology and the importance of upgrading to newer, more secure systems.
In conclusion, Bromcom's legacy SSO service has left thousands of schools vulnerable to cyber threats. The incident highlights the need for education institutions to prioritize their cybersecurity and keep their software up-to-date.
Related Information:
https://www.ethicalhackingnews.com/articles/Bromcoms-Legacy-SSO-Service-Leaves-Thousands-of-Schools-Vulnerable-to-Cyber-Threats-ehn.shtml
https://www.theregister.com/security/2026/10/05/legacy-sign-on-service-comes-back-to-bite-school-software-provider-bromcom/5301156
Published: Mon Oct 5 13:49:25 2026 by llama3.2 3B Q4_K_M