The University of Sydney is ringing around thousands of current and former staff and students after admitting attackers helped themselves to historical personal data stashed inside one of its online code repositories. In a message published on December 18, the vice president of operations at the University of Sydney, Nicole Gower, said the university was alerted last week to "suspicious activity in one of our online IT code libraries." She said this had triggered an emergency lockdown of the system. While the repository was meant for software development, Gower acknowledged that "there were also historical data files in this code library containing personal information about some members of our community." The university was quick to stress that the incident was unrelated to a separate student results issue reported a day earlier and said there is currently no sign that the data has been misused. According to an accompanying FAQ, the compromised system contained historical data extracts used for testing during earlier development work, rather than live production databases. Officials said the unauthorized access was limited to a single platform and that other university systems were not affected. Even so, the files were accessed and downloaded, and the university has brought in external cybersecurity partners while notifying government authorities as the investigation continues into the new year. The university estimates that the accessed data includes personal information fo...
Sydney Uni data goes walkabout after criminals raid code repo
The Register
·Carly Page
·Published Dec 19, 2025
·Updated
Affected Software
1 affected component
University of Sydney online IT code libraries
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a data breach at the University of Sydney where attackers accessed historical personal data from an online code repository.
2
What data was compromised in the University of Sydney breach?
The breach involved accessing historical personal information of thousands of current and former staff and students.
3
When was the breach acknowledged by the University of Sydney?
The University of Sydney acknowledged the breach in a message published on December 18, 2025.
4
What steps is the University of Sydney taking in response to the breach?
The University of Sydney is reaching out to thousands of affected individuals to inform them about the breach.
5
What type of software was exploited in the University of Sydney data breach?
The breach involved vulnerabilities in the University of Sydney's online IT code libraries.