2026 University of Western Australia — Callista SIMS credential exposure
Data compromised
Subset of student profile fields: name, UWA student ID, staff ID if applicable, phone numbers, DOB (day/month only), personal email, postcode, enrolment status as at 2 April 2026 — UWA said no financial details accessed
Technical writeup
Verified university notice. On 28 May 2026, UWA IT identified unauthorized external access to the Callista Student Information Management System after system access credentials were unintentionally exposed online. UWA said it secured the system, removed the vulnerability, and notified impacted prospective students, current students, and recent graduates. Exposed fields included names, student/staff IDs, phones, day/month of birth, personal email, postcode, and enrolment status as at 2 April 2026. UWA stated no financial details were accessed and there was no evidence of malicious use at the time of the notice. No public headcount of affected individuals was published on the university page at indexing.
Root cause
System access credentials for Callista Student Information Management System unintentionally exposed online, enabling unauthorized external access