SMBC Data Incident
September 2026
On 22 September 2026, SMBC became aware of unauthorised access to one SMBC email account. The account contained correspondence dating back several years, and some personal information may have been accessed (particularly data relating to SMBC past and current students, employees and suppliers).
We take the protection and privacy of your data very seriously, and we are committed to keeping you informed about important updates regarding your information.
What information was involved
The data may have included:
- Contact information (e.g. name, email address)
- For a small subset of affected individuals, data such as: Health information (specifically, dietary/allergy information), birth dates, and/or photos.
This appears to have been an isolated event. The data does not include:
- Passwords
- Credit card or sensitive financial information
- Identity Information (Centrelink information, Passport number, drivers licence etc)
We understand this may be concerning, particularly for people whose connection with SMBC is sensitive. We want to ensure that you are informed as we investigate the issue.
What we’re doing
Upon discovering this breach, we immediately took the following steps to contain and resolve the issue:
- We have secured the account from unauthorised access, and have ensured our database has not been accessed by unauthorised users.
- We are investigating to more accurately establish what information was involved, who may be affected and what steps to take.
- In accordance with data breach requirements we have notified the Office of the Australian Information Commissioner.
- Once we have confirmed the extent of the breach and determined the identity of subset of individuals affected, we will contact those individuals directly with information relevant to them and the recommended steps they should take.
- We are taking this seriously and strengthening our security measures as part of our response.
What you can do
If you have been affected, we will be in contact with more information directly, as soon as practicable.
We advise all individuals connected with SMBC to be cautious of unexpected messages claiming to be from SMBC, and be alert to spam and phishing attempts. If anyone is unsure whether a message purporting to be from SMBC is genuine, we ask them to email us at datasupport@smbc.edu.au before responding or sharing any information.
If you are concerned and want to take further action to protect yourself, you can find advice here:
Australian Government ESafety | What to do after a data breach: steps to protect against scams
OAIC | Data breach support and resources
How to contact us
If you have concerns in the meantime, please contact us at datasupport@smbc.edu.au
We will provide further updates as our investigation progresses.
In Christ,
Sydney Missionary & Bible College