Data leak

Western Sydney University data breach (2025) — 10,000 students

📅 2025-01-28 🏢 Western Sydney University SSO / identity management systems
Primary Source ↗

Incident Details

Unauthorised access to Western Sydney University’s systems via the SSO service occurred between 28 January and 25 February 2025. Approximately 10,000 current and former students notified 15 April 2025. Stolen data: names, dates of birth, email addresses, phone numbers, student admission and enrolment details, tax file numbers, passport numbers, driver’s licence details, and visa information. A former WSU student, Birdie Kingston (27), was arrested and charged with 20 offences including blackmail and accessing/modifying restricted data. This was WSU’s third breach in approximately one year. A second separate incident in June–September 2025 via a third-party cloud system exposed bank details and health records.

Technical Details

Initial Attack Vector
CWE-287: Improper Authentication (single sign-on (SSO) service compromised; insider/former student gained unauthorised access)
Vendor / Product
Western Sydney University SSO / identity management systems

Timeline

  1. 2025-01-28 Breach occurred
  2. 2025-04-15 Publicly disclosed
  3. 2025-04-15 Customers notified