Newcastle University disclosed unauthorised access to limited personal contact information caused by a configuration flaw in a connection to one of its admissions systems. The university was alerted on 27 July, corrected the issue and removed access; the affected information included names, postal addresses, email addresses and telephone numbers, but not admissions records or examination results.
Extortion group ExfilSquad claimed it stole about 440,000 records, although the university said its investigation had found no evidence supporting exposure of admissions or results data. Newcastle University notified the UK Information Commissioner's Office and engaged specialist security partners for forensic work, reporting no evidence of ransomware, malware, password or financial-data exposure, wider infrastructure compromise, or continuing attacker access. Affected individuals nonetheless face elevated phishing and impersonation risk from the exposed contact data.

See attribution, scope, and your downstream exposure.
4 events from the most recent confirmed update back to the earliest known activity.
Newcastle University disclosed that a configuration issue had enabled unauthorized access to limited contact data, including names, addresses, email addresses, and telephone numbers. It removed the access, corrected the issue, notified the UK Information Commissioner's Office, and said it found no evidence of ransomware, malware, wider-system compromise, admissions data, or examination results being exposed.
Newcastle University was alerted to potential unauthorized access to personal information. Its investigation later linked the access to a configuration issue in a connection to an admissions system.
The extortion-focused cybercrime group ExfilSquad posted claims involving 15 organizations, including the municipal governments of Atlanta and Houston.
ExfilSquad listed Newcastle University on its leak site and claimed it had stolen approximately 440,000 records, alleging the data included applicant and student contact details and other personally identifiable information. Newcastle University said its investigation had found no evidence that admissions records, examination results, passwords, or financial details were compromised.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.