1
Published signals
currently linked to this company
Company intelligence
westernsydney.edu.au
This company page brings together public reporting currently associated with Westernsydney. It reflects signals published by Shadow Tier and should not be read as a complete incident history.
Company links
1
currently linked to this company
0
recent published signals
0
recent published signals
1
confidence classifications
July 22, 2026
most recent published signal
Company signals
Public Notification – Western Sydney University cyber incident On 31 October 2024 Western Sydney University notified its community of unauthorised access to the University’s Student Management System and other back-end data storage systems, including the Data Warehouse from 14 August to 31 August 2024. On 11 February 2025, the University issued a correction and an update to the public notification, confirming: The unauthorised access to these systems occurred from 14 August to 3 September, three days longer than we originally notified on 31 October 2024. Additional personally identifiable information that may have been accessed, including first in family status and parent education level. This information is required as part of the enrolment process. The recommendations for impacted individuals remain the same and are outlined in the notification under the section ‘What action should you take?’. The University has updated the below public notification and has again drawn this notification to the attention of our former and current students and staff of the University, The College and The International College, staff of Early Learning Ltd. The University is committed to keeping our community updated through our investigation process and communicating transparently. Information about the support services the University has available are detailed in the public notification below. 31 October 2024 (corrected and updated on 11 February 2025) Western Sydney University issued this public notification on 31 October 2024, and draws this to the attention of our former and current students and staff of the University, The College and The International College, and staff of Early Learning Ltd. This public notification is for a separate cyber incident to the incidents that the University notified our community of on 21 May 2024 related to the University’s Microsoft Office 365 environment, and 31 July 2024 related to the University’s storage platform (Isilon), including My Documents. The University is issuing this notification to ensure that our community stays vigilant to any signs their data may have been accessed. Please consider all of your personal information that has been impacted across all the University’s cyber incidents and take seriously the recommended actions you can take to protect yourself. The University sincerely apologises for this incident and the ongoing impact it is having on our community. We are committed to transparently rectifying this matter and will keep our community updated as our investigation progresses. The University can confirm that an IT account was compromised which provided a perpetrator with unauthorised access to some data from the Student Management System and other back-end data storage systems including the Data Warehouse, from 14 August 2024 until 3 September 2024. Our investigation has confirmed names, addresses, University-issued email addresses, student identification numbers, tuition fee information (including fees deferred to HELP/HECS), student admission and enrolment data (including subject, results and progression information, and parent education level), and student demographic data (including nationality, Indigenous status, country of birth, citizenship status, gender, date of birth and first in family information) were accessed. The University has undertaken a preliminary analysis and can also confirm the following: On 27 August 2024, the University detected the unauthorised access and took immediate steps to protect our network in response. On 3 September 2024, the unauthorised access was contained. On 1 October 2024, the University’s investigation confirmed that personal information was accessed. As at 11 February 2025, our investigation into what data from the Student Management System and Data Warehouse was accessed confirmed the personal information listed above. As this investigation progresses, additional personal information may be found to have been accessed. There is no evidence to date that student records have been altered. The University has not received any threats to disclose private information or demands in exchange for maintaining privacy. The University has dark web monitoring in place and there is no evidence to date that the data has been uploaded. The University’s investigation to date indicates the perpetrator has used sophisticated techniques to gain unauthorised access in a targeted, persistent and sustained manner. What the University has done to secure personal information and mitigate harm Hacked again – new data breach at Western Sydney Western Sydney has experienced its second major data breach for the year, with the University yesterday announcing that a hacker accessed its Student Management System and the University’s Data Warehouse in August. The hacker gained access to the system on 14 August and was not detected until 27 August, accessing, “names, addresses, University-issued email addresses, student identification numbers, tuition fee information (including fees deferred to HELP/HECS), student admission and enrolment data (including subject, results and progression information), and student demographic data (including nationality, Indigenous status, country of birth, citizenship status, gender and date of birth)”. The University is still investigating the hack alongside police, and conceded that additional personal information may also have been accessed, however it has confirmed that no student records appear to have been altered. Around 7,500 individuals were affected by an breach of the University’s Isilon storage platform in January, with around 580 terabytes of data accessed across 83 of 400 storage directories. The first hack was revealed in May, “On behalf of the University, I unreservedly apologise for this incident and the impact it is having on our community,” Vice-Chancellor George Williams said. “We are committed to supporting our students, staff and stakeholders, and have several support services in place.” The University has not received any threats in relation to the breach and has promised ongoing upgrades to cyber security. Future Campus acknowledges Traditional Owners of Country throughout Australia. We pay our respect to Aboriginal and Torres Strait Islander cultures; and to Elders past and present.
FAQ
It combines a reviewed organization profile with all current published Shadow Tier signals explicitly linked to Westernsydney.
No. A signal must contain a reliable company connection and meet the publication criteria; incidental or ambiguous mentions are excluded.
The page follows current published reporting. Counts change as new evidence is added, classifications are reviewed, or older signals leave the reporting window.