Newcastle University has confirmed that a configuration flaw affecting a connection to one of its admissions systems allowed unauthorized access to personal information, including names, email addresses, telephone numbers and postal addresses.
The university identified the issue after being alerted to possible unauthorized access on July 27 and has since corrected the flaw. Officials said the investigation found no evidence that admissions records or exam results were exposed, and that passwords and financial details were not compromised. The university also said there is no evidence that its wider systems have been affected or that ransomware or malware was deployed.
“We believe there has been unauthorised access to some personal data through a specific technical vulnerability, which has now been resolved,” the university said in a statement. “At this stage, there is no evidence of broader compromise of our systems or infrastructure. We have found no evidence of ransomware, malware deployment or wider system compromise.”
The cybercrime group ExfilSquad has claimed responsibility for the intrusion, alleging it obtained about 440,000 records from the university, including applicant and student contact details along with other personally identifiable information, and has listed the material on its leak site. The university has not confirmed the number of records the group claims to have taken or whether the data was published, and its findings diverge from the group’s claims regarding the scope of what was accessed, particularly with respect to admissions information.
Newcastle University has not identified the specific system involved or detailed how the misconfiguration occurred. Specialist security partners are conducting further forensic analysis, and the university has notified the UK’s Information Commissioner’s Office.
The university said affected individuals do not need to take immediate action but should remain alert to phishing attempts, fraudulent calls, or impersonation scams that could use the exposed contact details to appear more credible. The university said it will never request passwords or payment by phone or email, and pointed those with concerns toward guidance from the UK’s National Cyber Security Centre, which similarly advises vigilance against phishing and prompt reporting of suspicious activity.
Newcastle University said it understands other organizations have been targeted by the same group and that it is coordinating with partners as its investigation continues.
ExfilSquad is an extortion-driven cybercrime group that pressures victim organizations into paying by threatening to release stolen data, warning on its leak site that published information remains permanently accessible and framing payment as cheaper than the fallout from a leak. The group has claimed attacks in recent weeks against organizations including Allstate, the District of Columbia Public Schools, and Pittsburgh-based supply chain company Wesco International. On July 26, it claimed to have targeted 15 organizations in a single day, including the municipal governments of Atlanta and Houston, and has also claimed breaches involving the UK Department for Education and the Police National Legal Database.