Victorian schools data breach: regulator finds a missed patch and records kept too long
Victoria's privacy regulator says the Department of Education broke two privacy requirements in the student data breach. What it found and what to copy.

Victoria’s privacy regulator has found that the state’s Department of Education broke privacy law in the breach that exposed the details of every government school student. Its report describes a failure many organisations will recognise: a warning to patch went out the same day, and there was no adequate way to check that it was acted on.
The Office of the Victorian Information Commissioner (OVIC) published its investigation report . Its page on the investigation was last updated on 7 October. The department told OVIC about the attack on 7 January 2026 and the investigation started that month.
What was taken
The attacker compromised the IT system of one of the department’s schools and reached a department database. According to the report, the information taken included every government school student’s first name and surname, the school they attend, their year level, and their school email address and encrypted password. The same details for hundreds of thousands of former students were in the database and were confirmed as affected.
OVIC says it was given no evidence of further misuse or disclosure immediately after the attack. It adds that the attacker made a copy and could misuse or disclose it later.
A name, school and year level can reveal where a child is. OVIC says that concern is greater for children and families experiencing or at risk of family violence, seeking asylum, covered by court orders protecting their safety, or living in foster or kinship care.
The patch that didn’t happen
Key dates from the report:
| When | What happened |
|---|---|
| 27 October 2025, 10.00am | The Australian Signals Directorate released a critical alert |
| 27 October 2025, 4.32pm | The department sent a directive to all school technicians |
| On or before 6 November 2025 | The attack occurred |
| 2 December 2025 | A vendor told the department it had detected significant threats |
| 23 December 2025 | Forensic analysis found data had been taken |
| 7 January 2026 | The department notified OVIC |
The report doesn’t name the vulnerability. It says schools were told about it, and how to patch the affected servers, on the day of the alert, and it refers to the department’s exposure to unpatched internet-facing servers. “However, not all schools followed the advice,” OVIC found, and the department “did not have adequate processes and procedures in place for assuring and monitoring whether schools acted on its directive”.
The school that was breached didn’t know until the department’s vendor picked it up through routine security monitoring. Even then, the report says, the department had difficulty getting schools to act on the urgency of patching.
OVIC also found the department’s vulnerability scanning program doesn’t cover every school, and that not all the critical vulnerabilities it finds are fixed. The department intends to move to centrally provided technology by the end of 2028. OVIC’s response is that the long lead time means the remaining risks have to be managed in the meantime.
Old records made it bigger
OVIC also looked at how long the department kept old records. The department told OVIC it kept former students’ credentials so a current student would never be issued an old email address and gain access to a former student’s data. OVIC found the department’s practices “were not a proportionate response” to that need.
The department says it will develop an archive policy for removing inactive student records by December 2026, and that implementing it needs more funding.
What OVIC decided
OVIC concluded the department contravened Information Privacy Principle 4.1 (take reasonable steps to protect personal information) and 4.2 (destroy or de-identify it when it’s no longer needed). These are rules for Victorian public sector organisations under the Privacy and Data Protection Act 2014.
It made seven recommendations, each due by 31 December 2026. They include a plan to align the department’s security practices with the Australian Cyber Security Centre’s Essential Eight, a “feedback loop” so the department knows schools have acted on security advisories, a review of how long past students’ credentials are kept, and more emphasis on cyber incidents in schools’ emergency planning. OVIC noted that the current emergency policy for schools is mostly about physical events such as fires and floods.
The department accepted the recommendations. Its response, published in the report, says it has started work on them and that “full implementation requires additional funding and resources, and will take time”.
If your child is or was at a Victorian government school
The Victorian Government’s incident page, updated on 5 October, says the third party did not access any other student or family data. It suggests reminding your child not to respond to unexpected or unknown emails.
If you’re worried about a current or past school location being known, the page says to contact the school, The Orange Door or Victoria Police on 131 444, or Triple Zero in an emergency. The department’s enquiry line is 1800 338 663.
Why it matters outside schools
Swap “schools” for branch offices, franchisees or an outside IT provider and the pattern is common: the head office sends the security notice, someone else is meant to apply it, and no one confirms it was done. Our Essential Eight explainer covers the baseline OVIC has pointed the department to, including patching. If personal information is taken from a business covered by the federal Privacy Act, the notifiable data breaches scheme may apply.
Checklist
- Ask for proof that urgent patches were applied. When you or your IT provider send out a critical security notice, require a reply from each site or device owner saying it’s done, and chase the ones that don’t answer.
- List every internet-facing server and who patches it. Include servers at branches, franchise sites and anything an outside technician looks after.
- Check what your vulnerability scanning covers. Ask your IT provider which locations and systems it doesn’t scan, and how quickly critical findings are fixed.
- Find the accounts and records of people who have left. Former customers, students, members and staff sitting in a live database are exposed in a breach too.
- Set a rule for removing inactive records. Decide how long each type is kept and who deletes or archives it, then put the first clean-up in the calendar.
- Add a cyber incident to your emergency plan. Write down who decides, who calls the IT provider and who tells the people affected.
Tick items as you go. Your ticks stay in this browser.




