UWA IT detected an unauthorized external intrusion into its Callista student information management system database. The breach path was established via system access credentials that were unintentionally exposed online. Compromised data included student names, IDs, staff IDs (where applicable), dates of birth (day and month only), home/mobile phone numbers, personal emails, postcodes, and April 2026 enrolment statuses. The university confirmed that no passwords, financial records, TFNs, or medical profiles were exposed. Impacted prospective students, current students, and recent graduates were notified on June 8.