This public notification is to inform Western Sydney University’s community about personal information that may have been impacted in a cyber incident, and to outline the steps people can take to protect their information.
I want to again apologise for the impact this is having and give you my assurance that we are doing everything we can to rectify this issue and support our community.
This starts with working closely with NSW Police Force Cybercrime Squad’s Strike Force Docker. On 25 June 2025, NSW Police arrested and charged a former student of the University.
Despite this, attempts to gain unauthorised access to our systems have continued, including via external parties that supply IT services to the University. In recent weeks, it has become clear that these incidents are intended to harm our community.
The University identified two instances of unusual activity on 6 August 2025 and 11 August 2025. This activity occurred on the University’s Student Management System, hosted by a third-party provider on a cloud-based platform.
An investigation commenced immediately, and the University directed the third-party provider to shut down access to its platform. The investigation confirmed that unauthorised access to this system was obtained through a further external system linked to that platform between 19 June 2025 and 3 September 2025.
Unauthorised entry through these third and fourth party systems enabled personal information to be accessed and exfiltrated from the University’s Student Management System.
The University’s investigations confirm that the fraudulent emails which were sent to some community members on 6 October 2025 used data stolen in this incident.
As soon as the University became aware, it reported the matter to NSW Police and the relevant regulatory authorities. NSW Police requested the University refrain from notifying its community at the time to avoid interfering with ongoing Police investigations.
NSW Police has now approved the release of today’s notification, which is for the attention of offer recipients, former and current students and staff of the University, The College, The International College, and staff of Early Learning Ltd.
The types of personal information that may have been impacted include:
The University will today issue individual notifications to those impacted by this incident. Some notifications will include personal information impacted through previous incidents, identified through ongoing investigations.
More information on previous incidents is available at: www.westernsydney.edu.au/cyberdetails.
You should consider changing your personal and University email account passwords and trying to make your password at least 15 characters, combining uppercase and lowercase letters, numbers, and symbols.
If you use the same password for your email account with your online banking, utilities and social media accounts, you should consider resetting your passwords for those accounts and setting up multi-factor authentication for each account. You may consider avoiding using the same password on multiple online accounts.
The University continues to engage IDCARE, Australia’s national identity and cyber support service. Contact IDCARE at www.idcare.org/contact/get-help or on 1800 595 160 for additional guidance on the steps you can take to protect yourself from the exploitation of your information and accounts.
Use the Referral Code WSUDB25 when lodging your request.
If you are not satisfied with the University’s response to the incident, you can request an internal review by providing the details of your matter via email to internalreview@westernsydney.edu.au. An internal review is a fact finding investigation into your privacy concern and how an incident has affected you. You should lodge the privacy internal review within six months after you first became aware of this incident.
If you are not satisfied with the actions taken by the University, you can lodge a complaint with the IPC within six months of when you first became aware of this incident. The IPC has more information about making a complaint, as well as your review rights, and can be contacted at:
Please note, this public notification will be published on the University’s public notification register from today's date (23 October 2025) for 12 months. This public notification will also be available on the Office of General Counsel’s website and the IPC’s website.
If you are an offer recipient, a staff member or student from The College or International College or a staff member from Early Learning Ltd and you are not satisfied:
We will continue to strengthen our cyber security capabilities to protect our students, staff and community and have engaged expert services at considerable cost to ensure that strong cyber protections are put in place. Some of the steps we’ve taken include but are not limited to:
The interim injunction previously granted to the University by the NSW Supreme Court continues to prohibit transmission, publication and use of any information or material obtained by the former student in an unauthorised manner from the University’s IT systems and network.
The University continues to work with cyber security experts and relevant authorities across Government, including the National Office of Cyber Security, Australian Federal Police and the Australian Signals Directorate’s Australian Cyber Security Centre.
Thank you for your continued attention to these notifications. It is important that you read them carefully and take the steps outlined.
The University’s investigations confirm that the fraudulent emails which were sent to some community members on 6 October 2025 used data stolen from the University.
Your personal information enters the University’s system shortly before an offer is made.
Individual notifications will be sent to impacted persons on 23 October 2025. This will include the specific list of personal information which has been compromised.
You also have the right to request further information from the University about how this cyber incident impacts you. To do this, send an email to internalreview@westernsydney.edu.au
The University has notified offer recipients, former and current students and staff of the University, The College, The International College, and staff of Early Learning Ltd.
This public notification has been made so the University community is aware of these cyber incidents and can take steps to protect themselves.
Individual notifications will be sent to impacted persons on 23 October 2025. This will include the specific list of your personal information which has been compromised.
You also have the right to request further information from the University about how this cyber incident impacts you. To do this, send an email to internalreview@westernsydney.edu.au
This notification is a statutory obligation for the University, which requires us to contact you directly.
The purpose of a public notification is so that you can be vigilant to any signs your data has been impacted, and to take steps to protect yourself. There are a range of resources available to you, including:
We will continue to strengthen our cyber security capabilities, prioritise our cyber security defences to protect our students, staff and community and have engaged expert services at considerable cost to ensure that strong cyber protections are put in place.
Some of the steps we’ve taken include, but are not limited to:
The University has worked collaboratively with NSW Police Force Cybercrime Squad’s Strike Force Docker. On 25 June 2025, NSW Police arrested and charged a former student of the University.
The University continues to work with cyber security experts and relevant authorities across Government, including the National Office of Cyber Security, Australian Federal Police and the Australian Signals Directorate’s Australian Cyber Security Centre.
If you are not satisfied with the University’s response to the incident, you can request an internal review by providing the details of your matter via email to internalreview@westernsydney.edu.au. An internal review is a fact finding investigation into your privacy concern and how an incident has affected you. Your should lodge the privacy internal review within six months after you first became aware of this incident.
If you are not satisfied with the actions taken by the University, you can lodge a complaint with the IPC within six months of when you first became aware of this incident. The IPC has more information about making a complaint, as well as your review rights, and can be contacted at:
Please note, this public notification will be published on the University’s public notification register from today's date, 23 October 2025, for 12 months. This public notification will also be available on the Office of General Counsel’s website and the IPC’s website.
If you are an offer recipient, staff member or student from The College or International College or a staff member from Early Learning Ltd and you are not satisfied: