Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-10-08 · updated: 2026-10-08 · tags: [incident, government] · confidence: high · severity: medium · affected_sectors: [government] · au_impact: true

The Office of the Victorian Information Commissioner's investigation report, published 5 October and covered 7 October, found the major breach of the Victorian Department of Education's student database — disclosed in January 2026, with the intrusion itself around early November 2025 — was caused by an impacted school failing to patch a critical server vulnerability despite a directive issued the same day as an Australian Signals Directorate alert on 27 October 2025. Attackers exploited the flaw to access and copy a database of current and former students, triggering a mass password reset before the school year. OVIC also criticised the department centrally: its vulnerability-management program does not cover all schools and does not ensure identified critical vulnerabilities are remediated, guidance for major-incident planning was insufficient, and retaining former students' credentials "to avoid email-address reuse" was a disproportionate risk that inflates breach impact. The department has pledged new threat-discovery tools, an archive policy for inactive student records by December, an internal audit next year and centrally provided vulnerability-management technology by end-2028 — a lead time OVIC warns leaves residual risk to manage meanwhile.

Attribute Detail
Sector Government
Date 2026-10-08
Source iTnews
Reliability Tier 3