ANU data breaches 'ongoing challenge' after sexual assault disclosures made public
Serious privacy concerns remain unresolved six months after the ANU was told that extremely sensitive information, including harassment and bullying disclosures, was viewable by all staff and students.
This article was originally published in the Canberra Times
Serious privacy concerns remain unresolved six months after the ANU was told that extremely sensitive information, including harassment and bullying disclosures, was viewable by all staff and students.
In December 2025, student reporters told the university's cyber security office that any staff or student logged into Microsoft 365 could access droves of sensitive information.
The reporters accessed spreadsheets outlining sexual assault, sexual harassment and bullying disclosures that included full names, contact details and allegations made by complainants by searching keywords.
They also sighted incident reports, student assignments, marking comments, security briefs, operation manuals and resumes. The reporters informed relevant departments of the breach so the sharing settings would be made private.
Screenshotted documents shared to The Canberra Times include a work health and safety incident report, including the full name of the employee who made the report, and a security brief preparing for a visit by then-Moroccan ambassador to Australia Karim Medrek.
Documents from the Fenner school of environment and society, such as a list of staff details including full addresses, personal numbers and emergency contact details, were publicly available as recently as June 11. They were immediately made private when reporters contacted the school.
A staff member said via email that "the amount of data that had been exposed is certainly very concerning".
In an email sent in December last year, student publication Woroni told security officials they would not publish an article about the breach until it had been resolved to protect the privacy of staff and students.
Reporters repeatedly asked the office of the chief operating officer, Michael Schwager, for updates via email throughout 2026.
On May 29, the office told reporters that the issues identified were "taken seriously" but that the sharing of private documents was "an ongoing challenge".
"The Information Security Office has been continuously working to identify and remediate externally shared permissions across the university's environment," the email said.
"A significant contributing factor is that users frequently generate shareable links - often without appreciating the access implications - which means new instances can arise faster than they are resolved."
The office said the ANU expected to launch "a comprehensive Microsoft 365 training program" later in the year to help "staff and students understand and manage sharing and permissions responsibly".
An ANU spokesperson told The Canberra Times that the university takes its privacy obligations seriously.
"When the university became aware of concerns regarding information associated with the Fenner school of society and broader Microsoft 365 issues, a comprehensive review was undertaken, and remediation activities were instigated to address identified issues," the spokesperson said.
"ANU has systems and processes in place for protecting and dealing with potential information, security or privacy breaches. Potential issues are assessed, prioritised and addressed through a structured remediation program.
"ANU encourages the responsible reporting of potential security issues. Concerns raised through established reporting channels contribute to the university's review and remediation activities."
Support is available for those who may be distressed. Phone Lifeline 13 11 14; Kids Helpline 1800 551 800; 1800-RESPECT 1800 737 732