Full Report
Intruders retrieved email addresses from superseded tech kept running for an internal system
Analysis Summary
# Incident Report: Compromise of Legacy Bromcom SSO Component
## Executive Summary
UK-based education software provider Bromcom suffered a data breach involving an unauthorized third party accessing a legacy Single Sign-On (SSO) registration component. The incident resulted in the exfiltration of user email addresses and registration metadata, though core Management Information Systems (MIS) and authentication credentials remained unaffected. The vulnerability existed because superseded technology was kept active to support a lingering internal system.
## Incident Details
- **Discovery Date:** September 6, 2026
- **Incident Date:** Prior to/on September 6, 2026
- **Affected Organization:** Bromcom Computers PLC
- **Sector:** Education Technology (EdTech)
- **Geography:** United Kingdom
## Timeline of Events
### Initial Access
- **Date/Time:** Exact start time not disclosed; identified September 6.
- **Vector:** Exploitation of legacy SSO registration functionality in the Communication Server environment.
- **Details:** Intruders targeted a superseded component that remained online to support an internal dependency.
### Lateral Movement
- **Details:** No evidence of lateral movement into the primary school Management Information System (MIS) or broader corporate network was reported.
### Data Exfiltration/Impact
- **Details:** Unauthorized retrieval of email addresses, SSO provider details (e.g., Microsoft, Google), registration dates, last sign-in dates, and internal reference numbers.
### Detection & Response
- **Discovery:** Detected following reports of SSO access issues.
- **Response actions taken:** Investigation launched with external forensic specialists; the vulnerable legacy functionality was decommissioned and withdrawn from production.
## Attack Methodology
- **Initial Access:** Exploitation of deprecated/legacy web functionality.
- **Persistence:** Not disclosed; likely transient access to the vulnerable component.
- **Privilege Escalation:** None reported.
- **Defense Evasion:** Not disclosed.
- **Credential Access:** None; the component did not store passwords or authentication tokens.
- **Discovery:** Scanning for legacy internal endpoints or superseded subdomains.
- **Collection:** Automated retrieval of user registration records from the Communication Server.
- **Exfiltration:** Direct retrieval of limited PII (email addresses).
- **Impact:** Information disclosure.
## Impact Assessment
- **Financial:** Costs associated with third-party forensic investigations and potential regulatory fines.
- **Data Breach:** Exposure of email addresses and sign-on metadata for an undisclosed number of users across 5,000+ schools.
- **Operational:** Disruption to SSO services and emergency decommissioning of internal system dependencies.
- **Reputational:** Public disclosure on education forums (EduGeek) and notification to major public sector clients (MoD, councils).
## Indicators of Compromise
- **Network indicators:** None provided in the public disclosure.
- **File indicators:** None provided.
- **Behavioral indicators:** Unusual access patterns to the legacy Communication Server SSO registration endpoint; reports of SSO service instability.
## Response Actions
- **Containment:** The legacy SSO registration functionality was immediately withdrawn from production.
- **Eradication:** Removal of the internal system dependencies that required the legacy tech to remain active.
- **Recovery:** Restoration of services using modern SSO protocols; customer notification via FAQs and community forums.
## Lessons Learned
- **Key takeaways:** Legacy code and superseded services represent a significant attack surface if not properly decommissioned.
- **What could have been done better:** Stricter enforcement of "End of Life" (EOL) policies for software components. Internal dependencies should have been migrated to current standards rather than keeping insecure legacy tech active.
## Recommendations
- **Asset Inventory:** Maintain a comprehensive inventory of all active services, including those supporting internal "legacy" dependencies.
- **Decommissioning Workflow:** Implement a formal process for disabling superseded code paths and ensuring no production environments host deprecated functionality.
- **Vulnerability Management:** Regularly scan for "shadow IT" or forgotten internal servers that may be exposed to the public internet.
- **Segmented Auth:** Continue the practice of separating authentication tokens/passwords from registration metadata to minimize impact in the event of a breach.