
Newcastle University has confirmed that a configuration issue affecting a connection to one of its admissions systems allowed unauthorized access to personal information, including names, addresses, email addresses, and telephone numbers.
The disclosure follows a claim by the ExfilSquad cybercrime group, which says it stole roughly 440,000 records from the UK university and published the data on its leak site.
The university said it was alerted to potential unauthorized access on July 27, 2026. Its investigation identified a configuration issue affecting a connection to an admissions system, which has since been corrected.
The university said it found no evidence of broader system compromise, ransomware, or malware deployment.
Misconfiguration exposed database information
Newcastle University has not disclosed the affected product or service, or the precise configuration error involved.
It said only that a configuration issue affecting a connection to an admissions system enabled unauthorized access to some contact information in its database. The configuration has now been corrected, and the university says the unauthorized access is no longer ongoing.
Forensic investigations are continuing with specialist security partners, while the university monitors its systems for suspicious activity and assesses its regulatory obligations.
The incident has also been reported to the UK's Information Commissioner's Office (ICO).
Newcastle University said other organizations are believed to have been targeted by the same criminal group, but did not identify them or provide further details.
ExfilSquad claims 440,000 records
ExfilSquad's leak site lists Newcastle University as one of the group's alleged victims and claims the stolen material contains approximately 440,000 records covering applicant and student contact information, personally identifiable information, and admissions data.

We have not downloaded the published archive and therefore cannot independently verify the authenticity, completeness, or contents of the data.
There is also a discrepancy between the attacker's claims and Newcastle University's findings. While ExfilSquad says the leak contains admissions data and “significant PII,” the university says the exposed information is limited to names, addresses, email addresses, and telephone numbers, with no admissions-related or exam results data affected.
Although the university says passwords, financial information, admissions records, and exam results were not exposed, contact information can still be used for phishing and impersonation attacks.
Criminals could use names, email addresses, phone numbers, and postal addresses to make fraudulent emails, calls, or text messages appear more convincing.
Newcastle University says affected people do not currently need to take action but should be alert for scams impersonating the institution. It stressed that it will never request passwords or payments by phone or email.
Students, applicants, and others who have shared contact information with the university should independently verify unexpected requests involving credentials or payments, avoid suspicious links and attachments, and follow guidance from the UK's National Cyber Security Centre for identifying and reporting phishing attempts.
Newcastle University says it will provide another update as its investigation progresses.







Leave a Reply