Skip to content
TECH CEO Daily

Frontline Education breach exposes school staff data; Bromcom intruders used retired login

A US edtech supplier, a UK school software firm and a Polish invoicing platform all disclosed intrusions, while Vicksburg, Mississippi, shut systems after ransomware.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1Frontline Education said a third-party software flaw let attackers reach part of its systems, exposing school employees' Social Security numbers.
  • 2Bromcom said a superseded single sign-on function stayed live because an internal system still called it, and attackers used it.
  • 3Fakturownia, used by over 600,000 businesses, said attackers reached its servers; Vicksburg shut systems after ransomware.

The news

Several organizations that serve schools, governments and small businesses disclosed security incidents in early October, and in most of them the weak point sat with a software supplier rather than the victim institution.

Frontline Education, which sells administration and workforce management software to US school districts, began notifying affected people on October 1, BleepingComputer reported. In its notification letter, the company said that on August 14 its security team identified a vulnerability in a third-party software product it uses that allowed unauthorized access to part of its environment. Exposed data included Social Security numbers, email addresses and physical addresses, according to BleepingComputer, which cited one district notification listing 1,210 affected employees. Frontline has not disclosed how many districts or people were affected, which third-party product was involved, or when the unauthorized access began. It is offering two years of credit monitoring through TransUnion, and districts have until October 16 to opt out of company-managed notifications.

In the UK, school software provider Bromcom said unauthorized parties accessed its legacy single sign-on (SSO) registration functionality, The Register reported. Bromcom said the function had been superseded but remained active because an internal system was still calling it. The company discovered the access on September 6 and announced it on September 24. It said email addresses, registration and last sign-in dates and internal reference numbers were retrieved, but the component did not hold passwords or authentication tokens and its school management information system was not affected. Bromcom serves more than 5,000 schools and 390 multi-academy trusts, according to The Register; it has not said how many were affected. It has withdrawn the legacy function.

In Poland, the online invoicing service Fakturownia, used by more than 600,000 businesses, said an attacker exploited a vulnerability to gain access to its servers, The Record reported on October 1. Exposed data included account details, password hashes, bank account information, authentication and integration tokens and invoices issued before 2023; payment card data was not affected. The company rotated passwords and keys. An attacker calling itself Fingerprint claimed to have taken 6 terabytes of invoices, a claim The Record said was unverified. Poland's Finance Ministry said its national e-invoicing system, KSeF, was not breached.

Separately, Vicksburg, Mississippi, a city of more than 20,000 people, shut down its computer systems after a ransomware attack, The Record reported on October 2. Utility payment processing was disrupted while emergency services kept running. Mayor Willis Thompson said a top priority was determining whether personal information of customers, contractors, vendors or employees had been compromised. The city has not named the attackers or said how they got in.

The numbers

Employees in one affected Frontline district
1,210
Schools served by Bromcom
5,000+
Businesses using Fakturownia
600,000+
Data claimed by Fakturownia attacker (unverified)
6 terabytes

Why CEOs should care

For CIOs and CISOs, Bromcom's explanation is the most useful detail: a login service everyone thought was retired stayed reachable because one internal system still depended on it. Ask for an inventory of every authentication endpoint your organization and its key vendors expose, including deprecated ones, and require that retired services be switched off, not just hidden.

For procurement and legal teams, Frontline's case shows a supplier's supplier can be the entry point. Contracts should require vendors to disclose their own critical third-party software, notify you within a fixed number of days, and delete your data when you leave. Offboarding a vendor without confirming data deletion leaves exposure on the table.

For boards of school districts, councils and companies alike, these incidents argue for treating vendor risk and asset inventories as governance issues. Ask how many vendors hold employee Social Security numbers or bank details, when each was last reviewed, and what the notification plan is if one is breached.

The bigger picture

Frontline and Fakturownia hold sensitive data for thousands of customers, so one intrusion reaches many organizations at once. Public bodies and small businesses rarely have the leverage or staff to audit suppliers closely, which makes shared standards and regulator scrutiny of software vendors more important.

What’s next

Frontline has set an October 16 deadline for districts to opt out of its notification service. Bromcom has not said how many people were affected, and Vicksburg has said it is still investigating whether personal data was accessed; further notifications may follow.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Frontline EducationBromcomFakturowniaVicksburgThird-party risk

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.