Confirmed 18 Dec 2025. Unauthorized persistent access to a legacy third-party IT code repository containing historical academic files. Exfiltrated student fields included full names, dates of birth, residential addresses, and phone numbers. No banking data was exposed; ACSC and NSW Privacy Commissioner notified.