Security1 publisher2 min readPublished
Bromcom removes a legacy SSO registration feature after a breach exposed users' email addresses
UK education software supplier Bromcom says unauthorized access to a legacy SSO registration feature exposed users' email addresses and reference numbers. Its school records system was not reached, so the question for schools is which older login features suppliers still run.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- Bromcom says account passwords and authentication tokens were not accessed in the incident.
- The company identified the issue on Sept. 6, following reports of trouble with SSO access.
- Bromcom is working with forensic specialists to establish the full scope of the breach.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Every account registered through the old feature is now on a list an outsider holds, with its sign-in provider and Bromcom reference number attached.
- decision Schools weighing forced SSO re-registration or credential resets have to decide before the forensic review reports, relying only on Bromcom's statement.
- constraint The issue came to light through access problems on Sept. 6. Until Bromcom dates the first access, schools have no start point for their own log checks.
Each retrieved record links an email address to registration details from an identity provider such as Microsoft or Google, and to an internal Bromcom user reference number [6]. If the company's statement on passwords and tokens holds, none of that opens an account [2]. It does make phishing more convincing. In my view the likely follow-on is email that names Bromcom, sends the recipient to a fake copy of the sign-in page they actually use, and quotes a reference number they have no way to check.
The entry point was a legacy SSO registration function inside the Communication Server environment [5]. Bromcom has since removed it [8]. The evidence that Bromcom no longer needed the feature comes down to two points. The reports describe it as legacy, and the company could switch it off after the incident [5][8]. The reports do not say whether customers still depended on it, how the access was obtained, how many accounts the registration data covered, whether those accounts belong to staff, parents or pupils, or who was behind it.
Removing the function stops further retrieval through that path. The records already retrieved stay with whoever took them [6][8].
Everything public comes from Bromcom's notice to customers, as reported by The Register and summarised by SC World [3]. On that record it is a single-supplier incident, with no link yet to a wider campaign against education software.
What to watch
- Bromcom's forensic findings: the number of accounts in the registration data, when access began, and whether the statement on passwords and tokens survives the review.
- Any party claiming the intrusion or publishing the data, which would move this from a single-supplier incident toward an actor with a pattern.
- Whether Bromcom or other UK education suppliers disclose retiring further legacy SSO or integration functions in the weeks after this notice.