Data breach
Arizona State University (ASU)
- Records
- 1,075,977
- Breach date
- 17 August 2026Estimated
- Added
- 8 September 2026
What was exposed
5 types of data
- Email addresses1,075,977
- Names813,045
- Phone numbers637,948
- Dates of birth543,957
- Street addresses455,932
About this breach
The Direwolf ransomware group has listed Arizona State University on its leak site, claiming it stole files from the public research university. According to our investigation team, the listing covers a dataset of about 1,075,977 records tied to asu.edu, with an estimated attack date of August 17, 2026. The group operates an extortion model in which victims are named publicly before any data is published, and ASU has not publicly confirmed the breach, as of September 25, 2026.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
Breach Timeline
August 17, 2026: Ransomware.live recorded the Direwolf listing for Arizona State University, with the same date given as the estimated attack date.
August 19, 2026: BreachSense recorded the breach report, listing DireWolf as the claiming actor.
What Information Was Compromised?
Our analysis found the following data types in this breach: names (813,045 records), email addresses (1,075,977 records), phone numbers (637,948 records), dates of birth (543,957 records), and street addresses (455,932 records).
The Direwolf listing itself claims stolen files but, per GalaxyWarden's review, does not detail specific records belonging to individual users, and no government identifiers such as Social Security numbers appear in the group's description. Because ASU has not confirmed the incident, the full scope of what was taken remains unverified.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The combination of names, email addresses, phone numbers, birth dates, and home addresses is enough to power convincing phishing and social engineering attacks. Scammers can use these details to pose as the university, a bank, or a government office, and a real birth date makes security questions easier to guess.
Contact details also feed identity theft attempts, since criminals can combine them with information gathered elsewhere to open accounts or file fraudulent claims in someone else's name. Separately, security firms monitoring asu.edu, including HudsonRock data reflected on Ransomware.live, have detected infostealer activity involving ASU-affiliated credentials. If any password tied to your university account circulated among criminals, attackers could attempt direct logins, especially if that password was reused on other sites.
What Should You Do If You Were Affected?
If you study or work at ASU, or have an account tied to an asu.edu address, take these steps:
Change your ASU password from a trusted device, and make it unique. If you used the same password anywhere else, change it there too.
Turn on multi-factor authentication for your ASU account if it is not already active. A second factor blocks most account takeovers even when a password leaks.
Review your account activity for unfamiliar logins, changed settings, or new recovery emails, and check any connected applications.
Be skeptical of unexpected contact. Treat calls, texts, or emails that cite your personal details, reference the university, or pressure you to act quickly as potential scams. Verify by contacting ASU directly through known channels, not by replying to the message.
Watch your accounts. Monitor bank and credit activity, and consider a credit freeze or fraud alerts with the major credit bureaus. Under federal law, you can also request free credit reports at AnnualCreditReport.com.
If ASU issues an official notice about this incident, follow its instructions and watch your university email for guidance.
