Unpatched server behind Vic student data breach

By
Follow google news

Departmental oversight and systems also criticised.

Key points

  • A school's delay in patching a critical server vulnerability, flagged by an Australian Signals Directorate alert on October 27 2025, led to a major Victorian Education data breach.
  • OVIC's investigation found the Department of Education provided insufficient guidance to schools and failed to ensure that critical vulnerabilities were remediated.
  • The department has pledged new threat discovery tools, an archive policy by December, an internal audit next year, and centrally provided vulnerability management technologies by the end of 2028.
Unpatched server behind Vic student data breach

A major Victorian Education data breach disclosed at the start of this year was caused by a school that delayed patching a critical server vulnerability, as well as central oversight weaknesses.

Unknown attackers exploited the vulnerability to gain access to and copy a database of current and former students, which led to a mass password reset just before the start of the school year.

The actual data breach occurred around early November 2025, but exfiltration was not confirmed until just before Christmas.

An investigation by the Office of the Victorian Information Commissioner (OVIC) found [pdf] that the impacted school had not patched a critical vulnerability, despite a directive to do so.

The directive was based on an Australian Signals Directorate alert sent on October 27 2025.

“Timely and effective patching did not occur at the school level,” OVIC found.

“The [directive] notified schools of the vulnerability and steps to remediate (patch) relevant servers on the same day. 

“However, not all schools followed the advice.”

Even after the data breach was detected and confirmed, the Department of Education “had difficulty … getting schools to act on the criticality of patching the vulnerability”.

The department also came in for criticism.

Although the department runs a vulnerability management program, where it “deploys technology to actively scan and report on vulnerabilities affecting schools”, not all schools are covered, and in those that are covered, “not all critical vulnerabilities identified are effectively remediated,” OVIC found.

OVIC also found that the department provides insufficient guidance to schools on “planning and preparing for a major cyber security incident.”

It also criticised the department for keeping the credentials of so many former students in the same database.

This has been an issue in many major data breaches in Australia, with data stored for far longer than it is needed.

Old credentials were kept on file “to ensure current students [would] not be issued the same email address which may give them access to the sensitive data of former students”.

However, OVIC found this was a disproportionate response to the problem.

Department of Education pledges action

The department said that since the cyberattack, it has “deployed additional threat discovery tools that have reduced the likelihood of similar risks happening again.”

It also intends to draft an “archive policy for the removal of inactive student records” by December, but actually implementing it will require “additional funding and resourcing”.
Additionally, it will perform an internal audit next year “to review the efficacy of its vulnerability management processes for schools.”

Looking further ahead, there are plans “to move to centrally provided technologies” for vulnerability management in schools “by the end of 2028.”

“While this represents an opportunity for strengthened ICT governance and risk processes, the long lead time means that the department must manage the remaining risks appropriately in the meantime,” OVIC wrote.

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

Home Affairs orders gov-wide 'legacy' system stocktake within six months

Home Affairs orders gov-wide 'legacy' system stocktake within six months

OpenAI agent accessed "credentials" via Medicare data portal

OpenAI agent accessed "credentials" via Medicare data portal

Cisco says no workaround for exploited SD-WAN Manager flaw

Cisco says no workaround for exploited SD-WAN Manager flaw

NSW National Parks web app accessed by OpenAI agent

NSW National Parks web app accessed by OpenAI agent

Log In

  |  Forgot your password?