ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Dutch university admits yearlong exposure of personal data in Power BI peporting tool

Avans University of Applied Sciences disclosed that sensitive personal data sat exposed to unauthorized users for almost a full year inside a management reporting tool built on Microsoft Power BI. The Dutch institution said it uncovered the problem earlier this month and has since notified everyone affected while alerting national privacy regulators.


The exposure occurred within AMIGO, an internal application Avans uses to track management information such as student enrollment figures and dropout statistics. The tool was constructed on top of Microsoft’s Power BI platform.


The vulnerability traced back to June 30, 2025, when a configuration change inside the Microsoft environment inadvertently made data traceable to specific individuals retrievable by people who should not have had access to it. The exposure went unnoticed for nearly twelve months until an Avans employee flagged on June 8, 2026, that the information was reachable by unauthorized users. The university moved quickly to close the gap and reported the incident to the Dutch data protection authority.


Avans declined to specify exactly what categories of personal data were exposed, stating only that the material was sensitive in nature. The institution noted that everyone impacted received individual notification on June 30, 2026, with a full explanation of which types of personal data were involved. "To protect the privacy of those affected, we’re not sharing that information. All those involved were personally notified on June 30th, 2026. It was explained exactly what type of personal data is involved," Avans said on a webpage set up to address the breach.


The university has opened an internal investigation, with security researchers examining why the exposure persisted undetected for close to a year. That review will also look at strengthening the monitoring and control systems meant to catch this kind of gap in the future.


Avans maintained that it had no evidence at this time that any of the exposed data was misused, though it has not ruled out that possibility. The institution added that the incident did not stem from a cyberattack and that the data was never made publicly available.


Avans also emphasized that although Microsoft owns the Power BI platform, responsibility for securing the data processed through it rests with the university itself. "We take that responsibility seriously, and you can hold us to it," Avans said.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543