Skip to content
Bromcom Reports Data Breach Linked to Legacy SSO System

Bromcom Reports Data Breach Linked to Legacy SSO System

First seen 8 Oct 2026, 16:41 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 8, 2026 at 17:35 UTC
  • •Bromcom's legacy SSO system was compromised, exposing email addresses and limited user data.
  • •No passwords or authentication tokens were accessed, and the main MIS remains secure.
  • •Bromcom is investigating the breach with external specialists and has removed the affected functionality.

Bromcom, a UK education software provider, has notified customers of a personal data breach involving unauthorized access to email addresses and limited information through a legacy single sign-on (SSO) service. The breach was identified on September 6, 2026, after users reported access issues. The affected legacy SSO functionality was part of Bromcom's Communication Server environment and has since been removed. No account passwords or authentication tokens were compromised, and the company's Management Information System (MIS) remains secure. Bromcom is collaborating with external forensic specialists to assess the breach's scope and is working with affected schools and authorities. The incident has raised concerns about the security of legacy systems still in operation.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-06
Breach identified
Bromcom discovered unauthorized access after reports of SSO access issues from users.
Teiss
2026-09-24
Public notification
Bromcom publicly notified customers of the breach on the EduGeek forum.
Teiss
2026-10-07
Breach reported by media
Scworld reported on the breach, summarizing the impact and Bromcom's response.
Scworld

More articles in this cluster (2)

Following this threat?

Track Bromcom in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What data was exposed?
Email addresses and limited information associated with SSO registrations were accessed.
Is my school affected?
If your school uses Bromcom's SSO technology, it may be affected; check with Bromcom for details.
What steps is Bromcom taking?
Bromcom has removed the affected legacy functionality and is working with forensic specialists to assess the breach.