TOP EDUCATION (01752) has implemented additional cybersecurity measures to prevent similar incidents in the future.

date
08:12 24/08/2026
avatar
GMT Eight
Australia Chengfeng Higher Education (01752) announced that the group has initiated an investigation and engaged cybersecurity and forensic experts to assess the scope of any unauthorized access or disclosure of personal data (if any) caused by the suspected incident (investigation). Upon learning of the suspected incident, the group also immediately took measures to identify any potential points of unauthorized access and took appropriate actions to sever the connection and access rights of the threat actors with SMS.
TOP EDUCATION (01752) announced that the Group has initiated an investigation and has engaged cybersecurity and forensic experts to assess the scope of the suspected incident involving unauthorized access to or disclosure of personal data (if any). Upon learning of the suspected incident, the Group immediately took measures to identify potential points of unauthorized access and took appropriate action to sever the connection and access rights of the threat actor to the Student Management System (SMS). According to the investigation results, an unauthorized third party (threat actor) gained access to the Companys Student Management System (SMS) using credentials stolen from an employee of the Group. Several personal data stored within the SMS (such as identity information, contact details, and enrollment information) may have been accessed or disclosed without authorization. The Group estimates that approximately 24,934 individuals, including prospective students, current students, alumni, and employees who are or have been in Australia, are affected by the suspected incident. The Group has reported the suspected incident to the Tertiary Education Quality and Standards Agency, the Australian Cyber Security Centre, the Australian Department of Education, and the Office of the Australian Information Commissioner. The Group has notified the affected individuals, reminding them to be alert to the suspected incident and the possibility of personal information being disclosed, and has provided relevant information on what steps can be taken to prevent potential misuse of personal data, as well as offering additional support. The Group has also implemented additional cybersecurity measures, including but not limited to resetting all employee account passwords, strengthening user authentication controls, implementing additional access restrictions, and other monitoring measures aimed at detecting and preventing further unauthorized access. The Group is committed to continuously enhancing the security of information systems to protect the personal data and privacy of all students and employees and to prevent similar incidents in the future.