Bromcom, a school software provider, has suffered an intrusion that exposed email addresses. According to The Register, the attackers gained access through a legacy sign-on service that had been superseded but was still being used for an internal system.

The incident is a reminder that replacing a primary system does not eliminate risk if older components remain active. In this case, the outdated authentication service was not part of the main external product, yet it still provided a way in.

The report specifically identifies email addresses as the data retrieved. While no further details are given, the exposure of such addresses can enable phishing campaigns and follow-on attacks.