Skip to Content
From Monday 12 September 2020, OVIC's website will no longer be supported in Internet Explorer (IE).
We recommend installing Microsoft Edge, Google Chrome, Safari, Firefox, or Opera to visit the site.

Investigation into the data breach of student information at the Department of Education

Last updated 7 October 2026

In January 2026, OVIC commenced an investigation into the cyber attack at the Department of Education. The attacker was able to compromise the Information Technology system of one of the Department’s schools and access student information. It was later discovered that the attacker was able to obtain the names, school of enrolment, year level and email addresses and passwords of hundreds of thousands of current and former government school students.

While there was no evidence provided to OVIC to indicate further misuse or disclosure of the information immediately after the cyberattack, it remains that a malicious attacker made a copy of that information and could misuse or disclose the information at some time in the future.

OVIC’s investigation considered whether the Department contravened the Information Privacy Principles (IPPs) and/or the Victorian Protective Data Security Standards.

The investigation found that the Department had interfered with the privacy of students’ information because its security controls were inconsistent with the requirements of IPP 4.1 and its record management practices were inconsistent with the requirements of IPP 4.2.

The report outlines a number of recommendations to improve vulnerability detection, patching, information security policies and practices and records management policies and procedures for both individual schools and the Department as a whole.

The Department acknowledged the concerns identified through the investigation and accepted that stronger measures are required to provide the level of assurance necessary to safeguard the personal information of students effectively. It stated that while the Department has undertaken substantial work to strengthen privacy, cyber security and child safety arrangements, it recognises that further improvements are necessary.

Download

20261005-Investigation-report-DE-Student-Information-Breach.docx

20261005-Investigation-report-DE-Student-Information-Breach.docx
Size 474.70 KB

Download
20261005-Investigation-report-DE-Student-Information-Breach.pdf

20261005-Investigation-report-DE-Student-Information-Breach.pdf
Size 314.46 KB

Download

Contents

Back to Index
Back to top
Back to Top