Top Education Group Ltd (Top Education) has provided further details on the unauthorised access to its Student Management System (SMS), first disclosed on 6 August 2026.
The investigation, conducted with external cyber-security and forensic specialists, confirmed that a threat actor gained entry through compromised staff credentials, exposing identity, contact and enrolment data. The incident potentially impacts roughly 24,934 individuals, covering prospective, current and former students as well as employees based in Australia.
Regulatory notifications have been lodged with the Tertiary Education Quality and Standards Agency, the Australian Cyber Security Centre, the Australian Government Department of Education and the Office of the Australian Information Commissioner. Affected persons have been informed and provided with guidance on safeguarding their personal information.
In response, Top Education has: • Reset all staff passwords. • Strengthened user-authentication protocols. • Imposed additional access restrictions. • Introduced enhanced monitoring to detect and block further unauthorised activity.
The board reiterated its commitment to reinforcing data-security measures and advised shareholders and potential investors to exercise caution when dealing in the company’s shares.