Legacy sign-on service comes back to bite school software provider Bromcom
Bromcom, a UK school software provider serving over 5,000 schools and 390 multi-academy trusts, has notified customers of a data breach affecting its legacy single sign-on (SSO) system. An unauthorised third party accessed email addresses and registration information associated with SSO accounts, with the incident discovered on 6 September and publicly announced on 24 September. The company has since withdrawn the superseded technology from production. The breach is noteworthy because of the scale of Bromcom's operations across the UK education sector, though the company has confirmed that the main Management Information System holding sensitive student data was not compromised.
The exposed data included email addresses, registration dates, last sign-in dates, and internal reference numbers linked to SSO registrations from providers such as Microsoft and Google. Importantly, the breach did not expose account passwords, authentication tokens, or provide access to the Microsoft and Google authentication services themselves. The legacy SSO functionality had remained in production because it continued to be called by an internal system, according to Bromcom. External forensic specialists are investigating the nature and scope of the incident, which the company is handling in liaison with affected schools, trusts, and the appropriate regulatory authorities.
- Legacy SSO system at UK school software provider Bromcom breached; email addresses exposed
- Main student data system not compromised; no passwords or Google/Microsoft account access
- Breach discovered 6 September; legacy system withdrawn from production
New here? Start with this
Bromcom is a software company that provides management systems for schools across the UK, serving over 5,000 schools and hundreds of multi-academy trusts. Someone gained unauthorised access to a legacy sign-on system the company was still using, exposing email addresses and account registration details.
The exposed information included email addresses, when accounts were registered and last used, and internal reference numbers, but not passwords or security tokens. The breach did not affect Bromcom's main student information system, which holds sensitive records about pupils.
This incident is significant because of how widely Bromcom's systems are used across the UK education sector. The legacy sign-on system had remained in operation because another part of the company's systems still relied on it. External specialists are investigating the breach.
Both sides, in good faith
The strongest fair case each way — we don't pick a winner.
The case for
Maintaining legacy systems in large enterprise deployments serving thousands of organisations is genuinely complex, as complete removal often carries significant operational risks. When the breach was discovered, Bromcom responded appropriately by engaging external forensics, promptly notifying stakeholders, and removing the vulnerable system. The actual exposure was limited to email addresses and metadata, with no compromise to student records, authentication credentials, or passwords—demonstrating that despite the legacy system's presence, core safeguards remained intact.
The case against
Allowing legacy systems to remain in production handling authentication across thousands of schools represents inadequate security governance. Regardless of technical complexity, companies must prioritise complete removal of superseded systems rather than deferring necessary work. The breach demonstrates that avoiding these difficult technical migrations creates preventable security incidents, and schools must insist upon higher security standards from their software vendors.