Hackers gained unauthorized access to an online code repository at the University of Sydney, resulting in the theft of historical files containing sensitive personal information. The breach, detected by the university's security team, exposed data belonging to over 27,000 individuals, including current and former staff, students, alumni, and a small number of supporters. The compromised data includes names, dates of birth, phone numbers, home addresses, job titles, and employment dates, primarily from records dating between 2010 and 2019. The university clarified that this incident is unrelated to other technical issues reported around the same time.
Upon discovery, the university immediately blocked access to the affected system and notified relevant authorities, including the New South Wales Privacy Commissioner and the Australian Cyber Security Centre. Impacted individuals are being informed through personalized notifications, and a dedicated support service has been established to assist those affected. As of now, there is no evidence that the stolen data has been published or used for fraudulent purposes, but the university continues to monitor the situation and has launched a comprehensive investigation expected to continue into January 2026.

See attribution, scope, and your downstream exposure.
7 events from the most recent confirmed update back to the earliest known activity.
The university started contacting impacted people on December 18, 2025, and said notifications would continue into January 2026 as the review progressed. It also published support resources, FAQs, and guidance on vigilance against fraud or misuse.
Following containment, the university notified authorities including the Australian Cyber Security Centre and the New South Wales Privacy Commissioner and launched an internal investigation with external support. The review was expected to continue into January 2026.
On December 18, 2025, the University of Sydney disclosed that a breach of its code repository exposed personal data of more than 27,000 current and former staff, students, alumni, affiliates, and supporters. The university said there was no evidence at that time that the stolen data had been published or misused.
The university's security team detected the intrusion in the code repository, blocked or revoked unauthorized access, and locked down the affected environment. It also purged exposed datasets and began working with external cybersecurity partners on remediation.
Hackers gained unauthorized access to an online IT code library or code repository used by University of Sydney IT teams and downloaded historical files containing personal data. The intrusion was limited to a single platform and did not affect other university systems.
The university previously experienced a distinct cyber incident in September 2023 involving a third-party service provider. Multiple reports state the 2025 code repository breach is unrelated to that earlier event.
The exposed records primarily dated from 2010 to 2019 and included historical personal information from a retired system, such as names, dates of birth, contact details, and employment-related data. Reporting indicates a key file related to staff employed as of 2018-09-04 was among the compromised data.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
6 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcethecyberthrone.in
Open sourcego.theregister.com
Open sourcecybersecuritynews.com
Open sourcetherecord.media
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.