"an unauthorized third party had accessed and retrieved email addresses and limited information associated with affected SSO registrations," wrote an account named Bromcom_Alastair on the EduGeek forum on September 24, describing a breach tied to the school software provider's single sign-on (SSO) system.
Bromcom's legacy SSO registration functionality
Bromcom, which supplies management information software to more than 5,000 schools and 390 multi‑academy trusts in the UK, said the incident involved legacy SSO registration functionality housed in its Communication Server environment. The company acknowledged the legacy component had remained in production after being superseded because "it was still being called by an internal system," and it has since withdrawn that functionality from production.
Scope of exposed data confirmed by Bromcom
According to a company FAQ and subsequent updates, the component that was accessed held email addresses associated with SSO registrations, the identity provider used for each registration (for example, Microsoft or Google), recorded registration and last sign‑in dates where present, and internal user and registration reference numbers. Bromcom said the affected component did not hold account passwords or authentication tokens.
The firm also stated it found no evidence that its school Management Information System (MIS) — the system used to manage student data, attendance, behaviour and administration — was compromised.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildDetection, containment and investigation
Bromcom reported that it first identified the issue on September 6 after customers reported SSO access problems. The company said it contained the incident and began investigating with external forensic specialists to determine the nature and scope of any data involved. In an updated comment added to the published story at 08:34 UTC on October 6, a Bromcom spokesperson said: "We recently identified, contained and began investigating an IT incident. Our investigation is ongoing to determine the nature and scope of any data involved, and we have already taken steps to resolve any disruption. We are liaising with the relevant schools and trusts, as well as the appropriate authorities."
Communications and market context
Bromcom has notified affected customers and is liaising with schools and multi‑academy trusts. The Register has asked Bromcom to comment further. The vendor's customer base, highlighted in the reporting, includes recent contract wins with Newport City Council, the Ministry of Defence, Warwickshire County Council, and the Northern Ireland Education Authority.
What this means for schools and trusts, technologists, and Microsoft/Google
- Schools and multi‑academy trusts: Bromcom says the MIS was not compromised and that it is liaising with the "relevant schools and trusts." Affected organisations will be watching forensic results and any further notifications from the vendor about which registrations were involved and how contact data might be used.
- Technologists and security teams: The incident centres on an older SSO registration component that remained active because it "was still being called by an internal system." Security teams will focus on the root cause of why a superseded component stayed in production, the completeness of the company's containment actions, and the external forensic report that Bromcom has commissioned.
- Microsoft and Google (identity providers named in the data): Bromcom expressly noted that the incident did not enable access to Microsoft or Google accounts because "their authentication services are separate from the affected component." Providers and administrators will nevertheless monitor reports for any evidence contradicting that separation and for potential phishing or follow-on misuse of exposed contact data.
In sum, the public record from Bromcom frames the event as a contained exposure of registration metadata — email addresses, provider names, dates and internal references — rather than account credentials or tokens, and asserts the MIS remained untouched. The company has pulled the legacy component from production and retained external forensic specialists to establish the full nature and scope of the data involved while it communicates with customers and the relevant authorities. How quickly that forensic work closes the remaining uncertainties will determine whether affected organisations view this as a limited data-retrieval incident or a longer-running operational failure tied to legacy code still reachable in production.




