Western Sydney University breach exposed records of 10,000 students

Organization
Western Sydney University
Exploit
Hacking
Industry
Education

Western Sydney University notified about 10,000 current and former students on April 15, 2025 that their personal information had been accessed in a compromise of one of the institution's single sign-on systems.

The university said the unauthorized access began on January 28, 2025 and continued through February 25. It became aware of potential unauthorized activity on February 8 and worked with internal and third-party cyber specialists to shut down known routes of access in real time, reset passwords, tighten account security and add monitoring tools.

The data involved consisted of student records rather than financial details. The university described it as personal demographic, enrolment and academic progression information.

Separately, the university said it had become aware of a dark web post dated November 1, 2024 that referenced personal information belonging to members of its community. Investigators associated that post with an earlier incident rather than the January intrusion. The university obtained an interim injunction in the New South Wales Supreme Court restricting access to and publication of the material, and the NSW Police Force Cybercrime Squad opened an investigation.

The April notification was the latest in a run of incidents. Vice-Chancellor George Williams described the university as facing persistent and targeted attacks and apologized to those affected. A separate compromise of the university's Microsoft 365 environment, disclosed in 2024, had affected roughly 7,500 people.

Sources