[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$flmVbBPPp5bfgjF9tyWkzaBhmvjqux3UiaKBPzjI-7zA":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"company":11,"breachDate":15,"addedDate":16,"modifiedDate":16,"pwnCount":17,"totalRecords":17,"dataClasses":18,"description":25,"source":26,"isVerified":4,"isSpamList":27,"isSensitive":4,"severity":28,"processingStatus":29,"logoUrl":30,"contentUpdatedAt":16,"hasEnglishDescription":4},"6a66c273a0199a9d0aead5e1","UniversityOfSydneyCodeLibrary2025","University of Sydney Code Library 2025 Data Breach","university-of-sydney-code-library-2025","sydney.edu.au",{"name":12,"sector":13,"country":14,"website":10},"The University of Sydney","Education","Australia","2025-12-18T00:00:00.000Z","2026-07-27T02:29:07.652Z",27506,[19,20,21,22,23,24],"Names","Dates of birth","Phone numbers","Home addresses","Job details","Historical student, alumni, and supporter personal information","\u003Cp>\u003Cstrong>The University of Sydney Code Library 2025 data breach\u003C\u002Fstrong> occurred when unauthorized access to an online library used for code storage and development exposed and downloaded historical files containing personal information. The institution learned of suspicious activity in December 2025, blocked access, and secured the environment. The university confirmed that the data was accessed and downloaded, not merely that viewing might have been possible.\u003C\u002Fp>\n\u003Cp>The disclosed categories are approximately 10,000 current staff and affiliates, 12,500 former staff and affiliates, 5,000 students and alumni, and six supporters. These values sum to 27,506, which this record uses for pwnCount and totalRecords. Because the first three categories were described as approximate, the figure should be read as the official category total and impact estimate rather than an exact deduplicated census.\u003C\u002Fp>\n\u003Ch2>How Was the Incident Confirmed?\u003C\u002Fh2>\n\u003Cp>The University of Sydney's official notice dated December 18, 2025 explains that a code library was compromised and contained historical data extracts with personal information. The updated page publishes the affected community groups, notification schedule, and response. The institution confirms that it blocked unauthorized access, purged the identified datasets from the repository, and informed relevant Australian authorities.\u003C\u002Fp>\n\u003Cp>The university's official FAQ says the incident was limited to one online platform and did not affect other university systems. BleepingComputer independently reported the institutional disclosure, confirming the download, group counts, and staff-data fields. LeakData uses the scope shared by these sources and does not speculate about the attacker's identity or an unpublished technical entry method.\u003C\u002Fp>\n\u003Ch2>Why Was Personal Data in the Code Library?\u003C\u002Fh2>\n\u003Cp>The affected platform was normally used for source-code storage and software development. The university said files containing personal information were historical extracts primarily created for testing when the code was developed. Retention of those extracts in a development environment allowed a compromise of the code repository to reach older community records.\u003C\u002Fp>\n\u003Cp>Staff data reflected people employed by or affiliated with the university as of September 4, 2018. Student and alumni files were mainly historical datasets from 2010 through 2019. These periods show that although the incident occurred in 2025, the information described relationships from years earlier; the age of the data does not automatically eliminate privacy risk.\u003C\u002Fp>\n\u003Ch2>Who and What Data Were Affected?\u003C\u002Fh2>\n\u003Cp>Approximately 10,000 current staff and affiliates and 12,500 former staff and affiliates were affected. Reporting based on the university's statements lists staff fields including names, dates of birth, telephone numbers, home addresses, and basic job or employment details. The record does not claim every field appeared for every person and limits the classes to the publicly described staff-file contents.\u003C\u002Fp>\n\u003Cp>The remaining category includes approximately 5,000 students and alumni in datasets mainly dated from 2010 to 2019, plus six supporters. The university confirmed access to historical personal information for these people but did not enumerate every student or alumni field on its public page. LeakData therefore uses a general class for historical student, alumni, and supporter personal information instead of inventing details.\u003C\u002Fp>\n\u003Ch2>How Did the University Respond?\u003C\u002Fh2>\n\u003Cp>After identifying suspicious activity, the university blocked unauthorized access to the online code library, secured the environment, and activated heightened security procedures for other systems. It purged the identified datasets from the repository and began an investigation to determine scope and identify affected people. External cybersecurity partners continued monitoring for signs that the information appeared online.\u003C\u002Fp>\n\u003Cp>The institution notified the NSW Privacy Commissioner, Australian Cyber Security Centre, Tertiary Education Quality and Standards Agency, National Student Ombudsman, and ID Support NSW. Current staff were notified in late December, notifications to former staff began in the week of January 19, and former students were contacted in the week of January 26. A dedicated support form, counseling, and identity-protection guidance were also provided.\u003C\u002Fp>\n\u003Ch2>What Should Affected People Do?\u003C\u002Fh2>\n\u003Cp>The university advised monitoring online, financial, and institutional accounts for unusual activity, changing passwords, and using multifactor authentication wherever possible. Messages that include an old telephone number, address, or job detail may appear credible. Calls and emails requesting more personal information should be verified through a separately obtained official channel before any response.\u003C\u002Fp>\n\u003Cp>At the disclosure and update dates, the university said it had found no evidence that the data had been published online or misused. That finding does not undo the confirmed download; it defines only the secondary use observed by that time. Suspected identity misuse can be reported to local law enforcement, the university cybersecurity team, and Australian support services such as ID Support NSW or IDCARE.\u003C\u002Fp>\n\u003Ch2>How Should This LeakData Record Be Read?\u003C\u002Fh2>\n\u003Cp>pwnCount and totalRecords are 27,506, the sum of the approximately 10,000, 12,500, and 5,000-person groups plus six supporters. Because the category figures are approximate, the final digits should not be interpreted as exact individual verification. breachDate is December 18, 2025, the verifiable official disclosure date; the university did not publish an exact first-access day, so an earlier day is not invented.\u003C\u002Fp>\n\u003Cp>importedRecordCount is zero, and LeakData stores no names, telephone numbers, addresses, dates of birth, job details, or historical student records. This entry summarizes the confirmed code-repository compromise, downloaded historical files, published category total, and response. If the investigation produces a deduplicated count or additional fields, the scope can be updated from the university's primary disclosure.\u003C\u002Fp>","Unauthorized access to an online code library containing historical personal-data extracts",false,"Medium","completed","\u002Fuploads\u002Flogo\u002Fsydney_edu_au.svg"]