Western Sydney University data breach leaves the information of more than 10,000 students vulnerable

In a recent data breach of Western Sydney University, an estimated 10,000 students’ personal information has been reported stolen. 

The university released a statement on 10 April 2025 outlining that the data breach occurred through the university’s single sign-on system, with two breaches occurring in January and February of 2025. The information that was accessed included academic information of students including their enrolment and progression, as well as personal demographic information. 

The university also confirmed in their statement that a post was made to the dark web on 24 March 2025, which involved the personal information of some members of the university community. Vice-Chancellor and President, George Williams AO, said “Western Sydney University has been the subject of persistent and targeted attacks on our network”.

“On behalf of the University, I apologise to our community. Our teams are working hard to respond and strengthen our digital environment.”

While the university has stated they are working with the police and third-party cyber experts to investigate the attack, this is not the first data breach that the university has experienced in the last year. The university issued a statement on 31 October 2024 explaining a range of personal data had been accessed, with details pertaining to students finances like tuition fee information (including fees deferred to HELP/HECS) and student demographic data, including information on nationality, Indigenous status, citizenship status, and date of birth. 

Critical cyber security issues like these raise concerns for the privacy and safety of student information. Western Sydney University currently enrolls over 47,000 students and is only one example of the growing issue of cyber security, particularly amongst large academic institutions. 

UNSW also uses a single sign-on system to grant students access to courses and enrolment information, the same system through which the initial breach occurred. 

Last year, cybersecurity expert and UNSW Professor Sanjay Jha, warned of the danger of overlooking such breaches and the unsafe impacts of data breach fatigue. Prof. Jha stresses the importance of recognising that personal data is a commodity that can be sold and exploited by those with malicious intent. 

“A lot of this information when it is obtained by a cyber-attack is then sold on the Darkweb and maybe it then gets bought by hackers who are building phishing sites designed to get the additional credentials they need to get into bank accounts and steal money” said Prof. Jha, reminding the community of the importance of taking data breaches seriously and protecting your personal data online.