Teiss Bromcom Reports Data Breach Linked to Legacy SSO System
Article Content
- •Bromcom's legacy SSO system was compromised, exposing email addresses and limited user data.
- •No passwords or authentication tokens were accessed, and the main MIS remains secure.
- •Bromcom is investigating the breach with external specialists and has removed the affected functionality.
Bromcom, a UK education software provider, has notified customers of a personal data breach involving unauthorized access to email addresses and limited information through a legacy single sign-on (SSO) service. The breach was identified on September 6, 2026, after users reported access issues. The affected legacy SSO functionality was part of Bromcom's Communication Server environment and has since been removed. No account passwords or authentication tokens were compromised, and the company's Management Information System (MIS) remains secure. Bromcom is collaborating with external forensic specialists to assess the breach's scope and is working with affected schools and authorities. The incident has raised concerns about the security of legacy systems still in operation.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Bromcom in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What data was exposed?
Is my school affected?
What steps is Bromcom taking?
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…