synaesthesia Posted September 24 Posted September 24 Has anyone else had word of a Bromcom SSO breach culminating but starting around a month ago? Had comms around the trust regarding this but can't see anything here, ANME or anywhere else!
psydii Posted September 24 Posted September 24 Not heard anything about that, but there was some chatter about Entra being busted which was buried in the 1000’s of the other CVE’s over the summer. Was otherwise distracted, so absent msm tech sites picking up the story, I assumed (head in the sand) it was a nothing-burger. An awful lot of ms infra software got vulnerabilities exposed recently.
synaesthesia Posted September 24 Author Posted September 24 According to the information sent out to some but very clearly not made public, it isn't related to Entra but specific to Bromcom. Not a huge breach for confidentiality purposes (no real PII for example) but user email addresses for staff & students, what SSO platform they use (MS or Google) and associated account, and PIN numbers in some cases (but apparently they're useless on their own) 1
Olliedawg Posted September 24 Posted September 24 First I've heard of this, not seeing any issues for our school yet either (MS SSO)
Popular Post Bromcom_Alastair Posted September 24 Popular Post Posted September 24 There has been an incident involving Bromcom's legacy Single Sign On service - this is a separate comms server unconnected to the MIS. Our investigation has shown an unauthorised third party has accessed and retrieved email addresses and limited information associated with SSO registrations associated with impacted accounts. Our team has thoroughly investigated and there is no evidence of any unauthorised access to the MIS or any data contained within the MIS. We are in the process of contacting all affected schools and we've created an FAQ which you can find on Community which gives more detail: https://community.bromcomcloud.com/announcements/post/sso-security-incident-hkgzAw8l0ADayVR Separately we are investigating an issue with SSO this morning, there is no evidence that this is related. We'll keep schools updated of any further detail via email, Community and on this thread. 5
synaesthesia Posted September 24 Author Posted September 24 Thank you Alastair, appreciated The bromcom community forum was one place I'd not checked this morning! 1 1
ultraspy2000 Posted September 24 Posted September 24 Hi all, Just wondering for those of you who've received the recent Bromcom security incident notification and how you are approaching it from a DPO/data breach perspective. We’ve been notified as some of our schools are affected. From Bromcom’s latest update, they have confirmed that an unauthorised third party accessed their legacy SSO (why are they still using old legacy SSO system? god knows why) registration service and retrieved personal data. The information involved includes email addresses, school name, Microsoft/Google sign-in provider, registration/last sign-in dates, internal reference numbers, school security codes and some PIN IDs. Both staff and pupil SSO registrations are affected, including some pupils using personal email addresses. Bromcom has confirmed that no passwords or authentication tokens were involved, there is no evidence that the MIS/database was compromised, and no evidence of successful unauthorised access to Bromcom/MIS accounts. They have identified the main potential risk as phishing, impersonation or social engineering. We’ve asked Bromcom for further information, particularly: A list of the specific staff/pupils affected and the data relating to them. Confirmation of which records were actually retrieved, rather than just deleted. Whether there is any evidence of the information being distributed or subsequently misused. Whether any further action is recommended for affected users. Whether Bromcom has reported the incident to the ICO and, if so, when. Further information to support our assessment of whether we need to notify the ICO and/or affected individuals. Bromcom’s current assessment is that the incident presents a risk to affected individuals but is not currently considered high risk. However, as data controllers, schools/trusts still need to make their own assessment. Interested to know how other schools/trusts are approaching this, particularly whether you have received the affected-user data from Bromcom yet and what next steps you are taking regarding the ICO and communication with affected staff/pupils. Thank you. 1
pete Posted September 24 Posted September 24 Looking at the school <> number of affected people counts for our schools, they're very close to staff Bromcom user numbers (albeit with one that's quite out of whack).
Seb1780 Posted September 25 Posted September 25 16 hours ago, pete said: Looking at the school <> number of affected people counts for our schools, they're very close to staff Bromcom user numbers (albeit with one that's quite out of whack). Does the number mean affected accounts? Ours says 1!
Bromcom_Alastair Posted September 25 Posted September 25 Hi Everyone - the Bromcom community posting has been updated with a direct link to an FAQ on this (it was a PDF before) - it can be reached here. We are aiming to update this as new questions come up. 1
synaesthesia Posted September 25 Author Posted September 25 Random question as we're not affected - what exactly is "Legacy SSO" in reference to please? We're only in our 2nd year so it may be that we've never seen any other type of SSO. 1
Seb1780 Posted September 25 Posted September 25 43 minutes ago, synaesthesia said: Random question as we're not affected - what exactly is "Legacy SSO" in reference to please? We're only in our 2nd year so it may be that we've never seen any other type of SSO. We're only 18 months in but we've been notified of an impact.
Olliedawg Posted September 25 Posted September 25 @Bromcom_Alastair please could you clarify what exactly the Legacy SSO is? Is this separate from the Microsoft/Google SSO?
pete Posted September 25 Posted September 25 2 hours ago, Seb1780 said: Does the number mean affected accounts? Ours says 1! That's how I read the notification to us, with the number in brackets following the Bromcom instance / school name being the number of affected accounts identified. Schoolname (32) Otherschoolname (123) etc.... @Bromcom_Alastair is that the total number of affected accounts (you've checked all of the accounts on an instance and only those are affected) or the number you've confirmed so far?
HC_Netman Posted September 25 Posted September 25 For us that number is almost double the number of active users that we have currently on the system which implies the legacy SSO was keeping a record of old user accounts as well. We have requested a list from Bromcom and we will decide what to do from there. We have never allowed personal email addresses to be used for signing in so it should only be school accounts.
Bromcom_Alastair Posted September 25 Posted September 25 2 hours ago, pete said: That's how I read the notification to us, with the number in brackets following the Bromcom instance / school name being the number of affected accounts identified. Schoolname (32) Otherschoolname (123) etc.... @Bromcom_Alastair is that the total number of affected accounts (you've checked all of the accounts on an instance and only those are affected) or the number you've confirmed so far? The number is based on a detailed technical investigation of the incident activity and associated records. The evidence identified through that investigation has been used to determine the affected records for each school. If any further investigation identifies a change to the figure provided for your school, we will update you directly.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now