Western Sydney University (WSU) has disclosed a significant data breach, raising concerns over the security of its Microsoft 365 and SharePoint platforms. The breach, detected in January 2024, revealed unauthorized access to the university’s email accounts and file repositories, impacting approximately 7,500 individuals.
According to WSU’s announcement, the breach, initiated on May 17, 2023, potentially compromised sensitive information stored within the university’s digital infrastructure. Investigations, involving specialists from the NSW Police, CrowdStrike, and CyberCX, suggest that the university’s Solar Car Laboratory infrastructure might have been exploited in the incident.
While the extent of data exposure varies among individuals, WSU assured that core operations remain intact, minimizing disruptions to academic activities and research programs. However, the university remains vigilant, with ongoing investigations to determine the full scope of the breach.
Despite the breach, WSU confirmed that no explicit threats or ransom demands have been received, indicating a lack of immediate extortion motives by the perpetrators. The university has also taken legal measures, securing an injunction from the NSW Supreme Court to prevent the dissemination of stolen data.
WSU has implemented enhanced security measures to prevent future incidents in response to the breach. Additionally, affected individuals are notified through personalized emails and phone calls, with support services readily available.
As WSU continues to address the aftermath of the breach, Australia’s national identity and cyber support service, IDCARE, has been engaged to provide further assistance. Meanwhile, the identity of the threat actors remains undisclosed, prompting heightened security measures and ongoing monitoring of the situation.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543