Static

Legacy sign-on service comes back to bite school software provider Bromcom

First reported by The Register ·

The signal ●○○○ Compiled by AI from The Register, the single source so far
Why you might care

Your email address may be exposed if you have an account with Bromcom. This could lead to phishing attempts or other targeted scams.

What happened

UK education software provider Bromcom has disclosed a data breach impacting its single sign-on (SSO) service. The incident, identified on September 6, involved unauthorized access to a legacy SSO registration functionality within Bromcom's Communication Server environment. Intruders successfully retrieved email addresses, registration details, and internal reference numbers associated with affected SSO accounts. Bromcom has confirmed that its core school Management Information System (MIS), which handles sensitive student data, was not compromised. The legacy component remained active because an internal system continued to call it. Bromcom has since removed this legacy functionality and is working with forensic specialists to determine the full scope of the breach. The company is also liaising with affected schools, trusts, and relevant authorities.

What it means

The incident highlights the persistent cybersecurity risks associated with maintaining legacy systems, even those superseded by newer technology. Bromcom's decision to keep the old SSO service running due to an internal dependency created a vulnerability that was exploited. This underscores the broader challenge for organizations, particularly in sectors like education with sensitive data, of balancing operational continuity with the imperative to retire outdated and potentially insecure infrastructure. The breach serves as a cautionary tale about the hidden costs and risks embedded in technical debt.

This event indicates a significant risk for educational institutions and their IT providers, emphasizing the need for rigorous security audits and proactive decommissioning of obsolete technology. It signals that attackers are actively probing for weaknesses in older, less-maintained systems that might offer easier entry points than modern, hardened infrastructure. Organizations using or providing software to the education sector should review their own legacy system management and incident response protocols to prevent similar incidents.

AI-written summary. May contain errors.

Legacy