More than 5,000 schools and 390 multi-academy trusts rely on Bromcom's software — and a legacy piece of that stack has just exposed personal data tied to single sign-on registrations.
How the intrusion occurred: legacy SSO registration in the Communication Server
Bromcom has notified customers that an unauthorized third party accessed a legacy single sign-on (SSO) registration component in the supplier's Communication Server environment. The company said the affected functionality was a legacy registration mechanism that had remained in production after being superseded because, in Bromcom's words, "it was still being called by an internal system."
The incident was first identified on September 6 after reports of SSO access problems, and the legacy functionality has been withdrawn from production while Bromcom works with external forensic specialists to determine scope and nature of the data involved.
What data was taken
Bromcom said the compromised component held email addresses associated with SSO registrations, the provider used for those registrations (for example, Microsoft or Google), recorded registration and last sign-in dates where available, and internal user and registration reference numbers. The company stated the affected component did not hold account passwords or authentication tokens.
According to a September 24 EduGeek post from an account named Bromcom_Alastair, an unauthorized third party "accessed and retrieved email addresses and limited information associated with affected SSO registrations."

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleTimeline and customer notification
According to Bromcom's disclosures, the supplier identified the issue on September 6 after users reported problems with SSO access. The public post notifying customers and the wider community appeared on September 24 on the EduGeek forum. Bromcom has confirmed it is engaging external forensic specialists to investigate.
In an FAQ cited by the vendor, Bromcom said its school Management Information System (MIS) — the platform used to manage student data, attendance, behaviour, and administration — showed no evidence of compromise.
Limits of the breach: authentication providers and account access
Bromcom emphasised that the incident did not enable access to Microsoft or Google accounts because those providers' authentication services are separate from the affected SSO registration component. The company also said passwords and authentication tokens were not held in the impacted service.
The Register has asked Bromcom to comment further.
What this means for schools, multi-academy trusts, and procurement/IT teams
- Schools and multi-academy trusts: organisations that use Bromcom's MIS and related services will be watching notifications about which users and emails were affected and may need to check local user records and communications to parents and staff where appropriate.
- Procurement and IT teams at customers (including recent customers named by Bromcom such as Newport City Council, the Ministry of Defence, Warwickshire County Council, and the Northern Ireland Education Authority): will need to confirm whether their implementations relied on the legacy registration path and coordinate with Bromcom on any remediation or audit activity.
- Microsoft and Google: while Bromcom says their authentication services were not exposed by the affected component, these providers will be one part of any follow-up verification where customers need reassurance that OAuth/identity flows and tokens were not implicated.
The immediate facts are straightforward: a superseded SSO registration component that remained callable by internal systems was accessed, some registration metadata and email addresses were taken, and Bromcom has removed the legacy functionality and engaged forensic experts. The event highlights the operational risk posed by dormant or superseded code paths still invoked by live systems. Bromcom's FAQ asserts no MIS compromise and no passwords or tokens were exposed; how confidence in that conclusion is reached will depend on the ongoing forensic work and any further disclosures the vendor makes to customers and regulators.
Original story: https://www.theregister.com/security/2026/10/05/legacy-sign_on_service_comes_back_to_bite_school_software_provider_bromcom/5301156




