# NSW Auditor-General

Type: government

Source: Cyber Intelligence Brief — https://getcyberbrief.com/entity/nsw-auditor-general
Canonical HTML page: https://getcyberbrief.com/entity/nsw-auditor-general

## Timeline

- **2026-06-22**: NSW Auditor‑General report published — Audit identifies 491 data incidents between 2023‑2025, critical gaps in policy versus practice, and lack of system‑level oversight of third‑party apps.
- **2025**: NSW student data breach occurs — Two students gain unauthorised access to 2,000 files containing mental health, disability, and behavioural information via a Microsoft 365 misconfiguration.
- **2022**: Human Rights Watch report released — Reviewed 163 government‑endorsed education apps in 49 countries, revealing widespread collection and sharing of children’s data for non‑educational purposes.

## Recent coverage (1 stories)

### Misconfigured Microsoft 365 Exposes 2000 Student Files in NSW Breach
2026-06-30 14:41:30 · Sentiment: Strongly negative · Impact: 7/10 · Sources: 3

A simple Microsoft 365 settings error allowed two students to access 2,000 confidential files, one of 491 cybersecurity incidents logged in a damning NSW audit. The report exposes systemic weaknesses in cloud configuration management and third‑party app vetting across the state’s schools.
Full story: https://getcyberbrief.com/story/microsoft-365-misconfiguration-nsw-education-breach

---
This page is a machine-readable summary. Sentiment measures the directional read of each development for this entity, not the tone of the reporting; impact weights consequence, not syndication reach. See https://getcyberbrief.com/guides/methodology for the full editorial methodology.