← SecureAZ Blog

Incident Response · 6 min read · Published 21 September 2026

The Perth School Breach: A Lesson for Every Organisation That Holds Family Data

St James Anglican School reported a breach exposing contact details, bank details, medical data and student photos. Most SMEs hold the same categories without realising it.

In mid-September, St James Anglican School in Perth reported a cyberattack that exposed student and family contact information, bank details, medical information and student photos. The school notified the Office of the Australian Information Commissioner, as the Notifiable Data Breaches scheme requires when a breach is likely to result in serious harm.

It is tempting to file this under "education sector problem." That would be a mistake. The useful exercise is to read the list of what was exposed and ask how much of it your own organisation holds.

The data range is the story

Four categories were reported exposed, and each lands differently:

  • Contact details — the raw material for targeted phishing against every affected family, for years
  • Bank details — direct financial fraud potential, and the category most likely to meet the "serious harm" notification threshold
  • Medical information — sensitive information under Australian privacy law, held by the school for entirely legitimate care reasons
  • Photos of children — the category with no remediation. A password can be reset; an image cannot be recalled

A typical 30-person business holds a strikingly similar spread: employee bank accounts for payroll, medical certificates and health disclosures in HR files, emergency contacts, and staff photos on the website and intranet. You are the same target with a smaller headline.

Why schools — and SMEs — get hit

Schools combine rich data with thin security resourcing, heavy email traffic with parents, and hundreds of users who never received security training. Swap "parents" for "customers" and that describes most small organisations. Attackers do not care about your sector; they care about that combination. The entry point in incidents like this is rarely exotic — credential phishing and unpatched remote access dominate, the same two doors we cover in warning signs of phishing attacks.

What the notification obligations actually require

In Australia, the Notifiable Data Breaches scheme requires notifying the OAIC and affected individuals when a breach is likely to cause serious harm — with a strong expectation of speed and specificity. In New Zealand, the Privacy Act 2020 sets an equivalent bar with the Privacy Commissioner. Two things trip organisations up in the moment:

  1. You cannot notify about what you cannot enumerate. If you do not know which records were in the exposed system, you end up notifying everyone about everything — maximum reputational cost, minimum precision.
  2. The clock runs from awareness, not from certainty. Waiting for a perfect forensic picture before starting the assessment is how organisations end up explaining delays to a regulator.

Both problems are solved before the breach, not during it: a data map (what is held, where, who can touch it) and a one-page response plan. We cover the first 24 hours in ransomware: what to do in the first 24 hours — the triage logic applies to any breach, encrypted or not.

Five actions this week

  1. List every system holding bank details, health information or images of people. It will be a shorter list than you fear and a more sensitive one than you assumed.
  2. Check who can access those systems and remove anyone who does not currently need to.
  3. Turn on MFA everywhere that list touches — our MFA guide for small business covers the order of operations.
  4. Confirm your backup for those systems is restorable, not just running.
  5. Put your staff through phishing and data-handling training that uses realistic local scenarios — because the entry point is almost always a person, not a firewall.

That last one is what SecureAZ does: short NZ/AU-specific awareness modules and realistic phishing simulations, with the audit trail that shows a regulator you took the people layer seriously. Start a free 45-day trial.

Sources & references