University of Sydney Hacked – Students and Staff Data Exposed
The University of Sydney has reported a significant data breach impacting thousands of current and former staff, students, and alumni.
The University of Sydney has reported a significant data breach impacting thousands of current and former staff, students, and alumni.
Vice-President (Operations) Nicole Gower announced that suspicious activity was identified in an online IT code library. This library, intended for software development, included outdated files containing sensitive personal data. Hackers gained unauthorized access to this library, where developers store and test code, and the university's security team swiftly blocked further access.
Despite halting the breach, an investigation revealed that historical files were downloaded by the intruders. These files, likely retained from testing activities, were not removed as expected. The breach is unrelated to a separate technical issue involving student results earlier this week.
Names Dates of birth Phone numbers Home addresses Job titles Employment dates
There is currently no evidence suggesting that the stolen data has been published online or used fraudulently. However, the university is closely monitoring the situation.
The University of Sydney has reported a significant data breach impacting thousands of current and former staff, students, and alumni.
The breach affects over 27,000 individuals, categorized as follows:
Current Staff: Approximately 10,000 employees as of September 4, 2018. Former Staff: Approximately 12,500 former employees from the same period. Students and Alumni: Over 5,000 individuals, primarily from 2010–2019, including a small number of supporters.
The University of Sydney has initiated a comprehensive investigation expected to continue into January 2026. Government authorities, including the Australian Cyber Security Centre and the NSW Privacy Commissioner, have been notified.
Affected individuals have been informed, and the university plans to reach all impacted persons by January 2026. Security experts advise potentially affected individuals to:
Be Alert: Beware of suspicious emails, texts, or calls requesting personal information. Scammers may use breached data for deception. Change Passwords: Update passwords for online accounts and use Multi-Factor Authentication (MFA) when available. Monitor Accounts: Regularly check bank statements and university accounts for unusual activity.
The university has established a Cyber Incident Support Form and is providing free counseling services for affected staff through Converge International.
Based on reporting by Cyber Security News.
