Newcastle University confirms unauthorised access to personal data

Newcastle University confirms unauthorised access to personal data

Newcastle University has confirmed that a configuration issue affecting a connection to one of its admissions systems enabled unauthorised access to personal information.

Newcastle University has confirmed unauthorised access to personal information after identifying a configuration issue affecting a connection to one of its admissions systems.

The University said it was alerted to potential unauthorised access on July 27 and subsequently identified a configuration issue that had enabled access to information held within its database.

According to a University statement, the affected information was limited to names, addresses, email addresses and telephone numbers. Newcastle University said admissions-related information and examination results were not affected.

The disclosure follows reports that cybercrime group ExfilSquad has claimed to have obtained approximately 440,000 records from the University and published the data on its leak site. Newcastle University has not confirmed either the number of records claimed by the group or the publication of the data in its statement.

The University said the technical issue has now been corrected to prevent further access and that its investigation has so far found no evidence of a broader compromise of its IT environment.

In its statement, Newcastle University said: “We believe there has been unauthorised access to some personal data through a specific technical vulnerability, which has now been resolved. At this stage, there is no evidence of broader compromise of our systems or infrastructure. We have found no evidence of ransomware, malware deployment or wider system compromise.”

The University is continuing forensic investigations with specialist security partners and assessing its regulatory obligations. It has also reported the incident to the Information Commissioner’s Office (ICO).

Newcastle University said its understanding is that other organisations have also been targeted by the same criminal group and that it continues to work with partners as investigations progress.

The University has advised individuals that they do not currently need to take any action but warned that anyone whose contact information was affected could receive scam emails, telephone calls or text messages purporting to originate from Newcastle University.

It stressed that the University will never contact individuals to request passwords or payments by telephone or email and directed those concerned about suspicious communications to guidance from the UK’s National Cyber Security Centre.

Offering his assessment of the incident, Muhammad Yahya Patel, vCISO & Cybersecurity Advisor, Huntress, said:

“The higher education sector keeps appearing in breach disclosures for a number of reasons. Universities operate vast, complex digital estates, student systems, research infrastructure, admissions platforms, and alumni databases, often with decentralised IT governance and inconsistent security standards across faculties and departments. That combination produces configuration gaps that attackers find before defenders do.

“A misconfigured system connection is a basic control failure. It should appear on any competent external attack surface assessment, and its correction should not require a criminal group to publish records on a leak site before the university discovers it. Students can’t audit the security of every system they interact with.”

Browse our latest issue

Intelligent Edu.tech

View Magazine Archive