Data breach
Newcastle University
- Records
- 425,677
- Breach date
- 26 July 2026Estimated
- Added
- 9 August 2026
What was exposed
3 types of data · 1 more reported
- Email addresses425,677
- Names359,988
- Phone numbers238,290
- Home addressesReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
Newcastle University has confirmed a data breach after the cybercrime group ExfilSquad claimed it stole roughly 440,000 records from the UK institution and published them on its leak site. According to our investigation team, the listing contains 425,677 records with an estimated attack date of July 26, 2026. The university says the unauthorized access stemmed from a configuration issue affecting a connection to one of its admissions systems, and that no evidence of ransomware, malware, or broader system compromise was found. Reporting by Cyberinsider indicates the university was alerted to potential unauthorized access on July 27, 2026.
The incident is part of a wider campaign. Researchers at Fortra identified ExfilSquad as a new data extortion group that first appeared on July 26, 2026, claiming access to data from 15 organizations. Fortra's analysis suggests the stolen data likely came from misconfigured Microsoft Dynamics 365 instances rather than a full compromise of university networks.
Breach Timeline
July 26, 2026: ExfilSquad publicly claimed the breach, listing Newcastle University on its leak site. The ransomware.live tracking service recorded the claim the same day.
July 27, 2026: Newcastle University was alerted to potential unauthorized access, according to Cyberinsider.
July 30, 2026: The university publicly acknowledged the breach, per reporting by Cypro.
August 7, 2026: ExfilSquad published data dumps for 13 victims, including Newcastle University, via torrents, according to Fortra.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses (425,677), names (359,988), and phone numbers (238,290).
The university itself has said the exposed information included names, addresses, email addresses, and telephone numbers, according to Cyberinsider. It stated that passwords, financial information, admissions records, and exam results were not exposed. ExfilSquad has claimed the leak contains admissions data and "significant PII," which conflicts with the university's account. The full contents of the published archive have not been independently verified.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Contact information alone may seem low risk, but it is exactly what criminals need to make scams convincing. Names, email addresses, phone numbers, and postal addresses can be combined to craft phishing emails, fraudulent phone calls, and text messages that appear legitimate, possibly referencing real details about university applications or studies.
People whose details were exposed should expect an increase in unsolicited contact. Scammers may impersonate the university, a government body, or a financial institution. Because the data is now published and may be mirrored across the internet, this exposure is effectively permanent.
What Is Newcastle University Doing in Response?
The university says it has corrected the configuration issue and that the unauthorized access is no longer ongoing. Its investigation, conducted with specialist security partners, found no evidence of ransomware, malware, or compromise of broader systems. The university has reported the incident to the UK's Information Commissioner's Office (ICO), is monitoring its systems for suspicious activity, and says other organizations are believed to have been targeted by the same group. It has committed to providing further updates as the investigation progresses.
What Should You Do If You Were Affected?
If you applied to or studied at Newcastle University, take these precautions:
Be skeptical of unexpected emails, calls, or texts referencing your application, student record, or payments. Verify requests through official university channels.
Remember that the university has stated it will never ask for passwords or payments by phone or email.
Do not click links or open attachments in unsolicited messages.
Follow the UK National Cyber Security Centre's guidance on spotting and reporting phishing.
The university says affected people do not currently need to take action, but staying alert to impersonation scams is wise.
In the news
- Cyberinsider: Newcastle University confirms data breach after ExfilSquad claims 440k recordscyberinsider.com (opens in a new tab)
- Ransomware.live: Newcastle University victim entryransomware.live (opens in a new tab)
- Fortra: ExfilSquad data extortion group analysisfortra.com (opens in a new tab)
- Cypro: Newcastle University Data Breach: ExfilSquad Claims Attackcypro.co.uk (opens in a new tab)
