www.upguard.com University Data Breaches Linked to Administrative Errors in 2026
Article Content
- •The University of Western Australia suffered a data leak due to exposed credentials.
- •Administrative errors, not external attacks, were the cause of multiple university breaches.
- •Exposed data includes sensitive personal information, increasing risks for identity theft.
In 2026, multiple universities, including the University of Western Australia (UWA), reported significant data breaches due to administrative errors. UWA's incident, disclosed on June 10, involved system access credentials for its Callista Student Information Management System being left exposed online, affecting personal data of current and former students. The breach was classified as medium severity, with exposed information including student IDs and dates of birth, raising risks for identity theft and phishing attacks. Other institutions, such as Newcastle University and Avans University, also faced similar breaches due to misconfigurations. These incidents highlight a recurring pattern in higher education, where decentralized IT governance leads to hygiene gaps in security practices. The breaches were not the result of sophisticated attacks but rather basic administrative oversights. Affected individuals are advised to update passwords and monitor for unusual activity.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Avans University Of Applied Sciences in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…