Unpatched server behind Vic student data breach

Key points

A school’s delay in patching a critical server vulnerability, flagged by an Australian Signals Directorate alert on October 27 2025, led to a major Victorian Education data breach.

Unpatched server behind Vic student data breach

Unpatched server behind Vic student data breach

Key points

  • A school’s delay in patching a critical server vulnerability, flagged by an Australian Signals Directorate alert on October 27 2025, led to a major Victorian Education data breach.
  • OVIC’s investigation found the Department of Education provided insufficient guidance to schools and failed to ensure that critical vulnerabilities were remediated.
  • The department has pledged new threat discovery tools, an archive policy by December, an internal audit next year, and centrally provided vulnerability management technologies by the end of 2028.




Unpatched server behind Vic student data breach








A major Victorian Education data breach disclosed at the start of this year was caused by a school that delayed patching a critical server vulnerability, as well as central oversight weaknesses.

Unknown attackers exploited the vulnerability to gain access to and copy a database of current and former students, which led to a mass password reset just before the start of the school year.

The actual data breach occurred around early November 2025, but exfiltration was not confirmed until just before Christmas.

An investigation by the Office of the Victorian Information Commissioner (OVIC) found [pdf] that the impacted school had not patched a critical vulnerability, despite a directive to do so.

The directive was based on an Australian Signals Directorate alert sent on October 27 2025.

“Timely and effective patching did not occur at the school level,” OVIC found.

“The [directive] notified schools of the vulnerability and steps to remediate (patch) relevant servers on the same day. 

“However, not all schools followed the advice.”

Even after the data breach was detected and confirmed, the Department of Education “had difficulty … getting schools to act on the criticality of patching the vulnerability”.

The department also came in for criticism.

Although the department runs a vulnerability management program, where it “deploys technology to actively scan and report on vulnerabilities affecting schools”, not all schools are covered, and in those that are covered, “not all critical vulnerabilities identified are effectively remediated,” OVIC found.

OVIC also found that the department provides insufficient guidance to schools on “planning and preparing for a major cyber security incident.”

It also criticised the department for keeping the credentials of so many former students in the same database.

This has been an issue in many major data breaches in Australia, with data stored for far longer than it is needed.

Old credentials were kept on file “to ensure current students [would] not be issued the same email address which may give them access to the sensitive data of former students”.

However, OVIC found this was a disproportionate response to the problem.

Department of Education pledges action

The department said that since the cyberattack, it has “deployed additional threat discovery tools that have reduced the likelihood of similar risks happening again.”

It also intends to draft an “archive policy for the removal of inactive student records” by December, but actually implementing it will require “additional funding and resourcing”.
Additionally, it will perform an internal audit next year “to review the efficacy of its vulnerability management processes for schools.”

Looking further ahead, there are plans “to move to centrally provided technologies” for vulnerability management in schools “by the end of 2028.”

“While this represents an opportunity for strengthened ICT governance and risk processes, the long lead time means that the department must manage the remaining risks appropriately in the meantime,” OVIC wrote.



About Author

What do you feel about this?

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.