Full Report
Intruders retrieved email addresses from superseded tech kept running for an internal system
Analysis Summary
# Incident Report: Compromise of Legacy Single Sign-On (SSO) Component
## Executive Summary
UK-based education software provider Bromcom suffered a data breach involving an unauthorized third party accessing a legacy Single Sign-On (SSO) registration component. The intruders retrieved email addresses and registration metadata, though no passwords or authentication tokens were stored in the affected system. The breach originated from superseded technology that remained active in production to support an internal dependency.
## Incident Details
- **Discovery Date:** September 6, 2026
- **Incident Date:** Ongoing/Identified September 2026
- **Affected Organization:** Bromcom
- **Sector:** Education Technology (EdTech) / Business Software
- **Geography:** United Kingdom
## Timeline of Events
### Initial Access
- **Date/Time:** Pre-September 6, 2026
- **Vector:** Exploitation of legacy SSO registration functionality.
- **Details:** Intruders targeted a superseded Communication Server environment that remained operational because it was still being called by an internal system.
### Lateral Movement
- **Details:** No evidence was found of lateral movement into the primary school Management Information System (MIS) or broader administrative environments.
### Data Exfiltration/Impact
- **Data Stolen:** Email addresses, SSO provider identities (e.g., Google, Microsoft), registration dates, last sign-in dates, and internal user/registration reference numbers.
### Detection & Response
- **Discovery:** September 6, 2026, following reports of SSO access issues.
- **Response actions taken:** The legacy functionality was withdrawn from production; external forensic specialists were engaged; regulatory authorities and customers were notified.
## Attack Methodology
- **Initial Access:** Exploitation of superseded/legacy software functionality.
- **Persistence:** Not explicitly disclosed; likely via the exposed legacy API/service.
- **Defense Evasion:** The vulnerability existed in a "shadow" capacity (legacy tech supporting an internal system), which often bypasses standard patch cycles.
- **Collection:** Automated retrieval of SSO registration records.
- **Exfiltration:** Data retrieval via the compromised legacy SSO component.
- **Impact:** Unauthorized access and disclosure of Personal Identifiable Information (PII).
## Impact Assessment
- **Financial:** Costs associated with external forensic investigations and potential regulatory fines (ICO).
- **Data Breach:** Compromise of email addresses and metadata for users across potentially 5,000 schools and 390 trusts.
- **Operational:** Disruption to SSO services and emergency decommissioning of legacy components.
- **Reputational:** Public disclosure required via EduGeek and media outlets, affecting trust with UK local councils and the Ministry of Defence.
## Indicators of Compromise
- **Behavioral indicators:** Unusual SSO access patterns; reports of SSO registration failures or anomalies starting around early September.
- **Network indicators:** [Defanged] Requests directed at legacy Communication Server endpoints (e.g., hxxps[://]docs[.]bromcom[.]com/...).
## Response Actions
- **Containment:** Withdrew the legacy SSO registration functionality from the production environment.
- **Eradication:** Decommissioned the superseded technology that was still being called by internal systems.
- **Recovery:** Engaged external forensics to validate the scope of the breach and ensure the MIS environment remained isolated.
## Lessons Learned
- **Technical Debt Risk:** Keeping superseded technology active to support internal systems creates a significant "blind spot" for security teams.
- **Inventory Management:** Legacy components must be fully decommissioned or strictly isolated once replaced by newer versions.
- **Dependency Mapping:** The organization failed to identify that an internal system still relied on a vulnerable, superseded component.
## Recommendations
- **Asset Decommissioning:** Establish a formal "sunset" policy for legacy code, ensuring all internal dependencies are migrated before decommissioning.
- **Vulnerability Scanning:** Ensure that legacy or "internal-only" systems are included in regular penetration testing and vulnerability assessments.
- **Zero Trust Architecture:** Implement stricter segmentation between legacy internal support systems and public-facing registration components.