Teiss Dutch University Exposes Personal Data for Nearly a Year via Power BI Tool
Article Content
- •Avans University exposed sensitive personal data for nearly a year due to a configuration error.
- •The breach was discovered by an employee on June 8, 2026, after going unnoticed since June 30, 2025.
- •The university has launched an investigation and reported the incident to national privacy regulators.
Avans University of Applied Sciences revealed a yearlong exposure of sensitive personal data through its internal management reporting tool, AMIGO, built on Microsoft Power BI. The breach originated from a configuration change on June 30, 2025, allowing unauthorized access to data traceable to individuals. The issue was discovered by an employee on June 8, 2026, prompting immediate action to close the vulnerability and notify affected individuals. The university reported the incident to the Dutch data protection authority and has initiated an internal investigation to understand why the exposure went undetected for so long. While the university has not disclosed the specific types of personal data exposed, it confirmed that the data was sensitive in nature. Avans maintains that there is no evidence of data misuse and that the incident was not the result of a cyberattack. The responsibility for securing the data lies with the university, despite Microsoft owning the Power BI platform.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Avans University Of Applied Sciences in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…