← University of Western Australia

2026 University of Western Australia — Callista SIMS credential exposure

2026 Unknown records affected Share on X

Data compromised

Subset of student profile fields: name, UWA student ID, staff ID if applicable, phone numbers, DOB (day/month only), personal email, postcode, enrolment status as at 2 April 2026 — UWA said no financial details accessed

Technical writeup

Verified university notice. On 28 May 2026, UWA IT identified unauthorized external access to the Callista Student Information Management System after system access credentials were unintentionally exposed online. UWA said it secured the system, removed the vulnerability, and notified impacted prospective students, current students, and recent graduates. Exposed fields included names, student/staff IDs, phones, day/month of birth, personal email, postcode, and enrolment status as at 2 April 2026. UWA stated no financial details were accessed and there was no evidence of malicious use at the time of the notice. No public headcount of affected individuals was published on the university page at indexing.

Root cause

System access credentials for Callista Student Information Management System unintentionally exposed online, enabling unauthorized external access

References