Newcastle University has confirmed that a configuration issue affecting a connection to one of its admissions systems allowed unauthorized access to personal information held in its database, after the data extortion group ExfilSquad listed the university on its dark web leak site and claimed roughly 440,000 stolen records. The university says it was alerted to potential unauthorized access on 27 July 2026, has since corrected the configuration, and has reported the incident to the UK's Information Commissioner's Office. Newcastle is the only non-government UK entity publicly named so far in a wider ExfilSquad campaign that also hit the Department for Education and the Police National Legal Database.
What Happened
According to the university's own statement, as reported by CyberInsider, Newcastle was alerted on 27 July 2026 to potential unauthorized access to personal data. Its investigation identified a configuration issue affecting a connection to an admissions system, which enabled unauthorized access to contact information held in a university database. That configuration has been corrected and the university says the unauthorized access is no longer ongoing. Forensic work continues with external specialist security partners while the university monitors for further suspicious activity and assesses its regulatory obligations.
Critically, the university states it found no evidence of broader system compromise, and no evidence of ransomware or malware deployment. It has not disclosed the affected product or service, nor the precise nature of the configuration error. It also said other organizations are believed to have been targeted by the same criminal group, without naming them.
The timeline lines up almost exactly with the rest of the campaign. ExfilSquad listed PNLD on 26 July, the same day that intrusion was detected, and posted DfE and PNLD samples on 26 July per IBTimes. Newcastle's alert on 27 July puts it inside the same window. DarkOwl notes that every victim on the group's leak site carried an identical ransom deadline of 05.08.2026, which points to one coordinated extortion push rather than a series of separate intrusions.
Accounts differ on the size of the victim set. DarkOwl reported 15 alleged victims across the United States (9), United Kingdom (3), Sweden (1) and Nigeria (1), while listing 14 named entities. IBTimes UK reported 14 alleged victims across five countries, and The Canary reported that ExfilSquad itself claimed to have targeted 14 institutions. SOFX also cites 15 victims across five countries. Treat the count as roughly 14 to 15 claimed victims, most of them still independently unverified, including a claim against Microsoft.
What Was Taken
Newcastle University has confirmed that the exposed information includes names, addresses, email addresses and telephone numbers. It has not published a figure for the number of records or individuals affected.
The 440,000 record figure comes solely from ExfilSquad's leak site, which claims the stolen material covers applicant and student contact information, personally identifiable information, and admissions data. That number is the attacker's claim, not a university-confirmed count, and extortion crews routinely inflate or double-count. The Canary reports that the stolen data includes names, addresses and phone numbers of both staff and students, which is broader than the applicant-and-student framing on the leak site; that staff element rests on a single OTHER-tier source and should be treated as unconfirmed.
The gap between claimed and confirmed figures is visible elsewhere in the same campaign and is instructive here. For PNLD, ExfilSquad claimed a 1.9 GB dataset of approximately 135,000 records; BleepingComputer reported more than 100,000 officers and staff affected; and SOFX, citing the North East Regional Organised Crime Unit, put it at roughly 114,000 police and criminal justice professionals plus around 21,000 members of the public who used the Ask the Police service. For DfE, The Times and Computer Weekly reported more than 600,000 records, while the department itself confirmed approximately 607,000, stressing these are total records rather than distinct individuals. Expect Newcastle's eventual confirmed figure to be framed the same way, in records rather than people.
No source in this set indicates that passwords, credentials, or financial data were taken at Newcastle. PNLD explicitly stated no evidence of compromised passwords or authentication data, and DfE said no bank details or other highly sensitive information were involved.
Why It Matters
This is a contact-data breach, and the reflex is to underrate it. That is a mistake. Jake Moore of ESET, quoted in The Canary's coverage, notes that experienced threat actors treat leaked contact sets as highly valuable precisely because they enable personalised follow-up phishing and social engineering that pulls in far more sensitive data. Commentary in Computer Weekly's DfE coverage makes the same point about piecing together a data jigsaw into convincing follow-up lures.
For Newcastle specifically, the population is applicants and students, many of them in the middle of an admissions cycle and primed to open unsolicited email about offers, fees, accommodation and visa paperwork. That is close to an ideal pretext environment. Applicant PII also has long-tail value: an 18-year-old's name, home address and phone number does not rotate the way a password does.
The wider campaign context matters too. ExfilSquad went from unknown to claiming Microsoft, Allstate, Frontier Airlines, Zenith Bank, the City of Houston, the City of Atlanta, DC Public Schools and Bonava inside roughly a week, per DarkOwl's victim listing. The group's own public posture, quoted by The Canary, is pure litigation-cost arbitrage: pay a rounding error now or eat the disclosure costs later. Notably, NEROCU told investigators that no ransom demand had been received in the PNLD case, which directly conflicts with the group's extortion framing and with BleepingComputer's report that a ransom was demanded of PNLD. Whether ExfilSquad is reliably making contact before publishing is genuinely unclear.
The Attack Technique
Newcastle has not named the affected product or described the configuration error, so the specific mechanism at the university is not confirmed by any primary source.
The most substantive technical hypothesis in the reporting comes from cybersecurity firm VenariX, cited by SOFX. VenariX found data structures consistent with Microsoft Dataverse across 11 of the claimed victims and assessed the likely access path as misconfigured public Power Pages portals, sites that can allow unauthenticated visitors to read backing database tables directly. VenariX said it found no evidence of ransomware, malware, or software vulnerability exploitation in the campaign material it examined. That is one vendor's assessment reported through a single OTHER-tier outlet, not a confirmed finding, but it is strikingly consistent with Newcastle's own language about a configuration issue affecting a connection to an admissions system, with no malware and no broader compromise.
The other campaign victims show at least one different entry path. Computer Weekly reported, based on The Times, that DfE was hit through a social engineering attack against an internal helpdesk used by school and university staff and local authorities, with data taken from its Help Desk Self-Service Portal and Turing Scheme Portal. PNLD has not disclosed how attackers got in, and West Yorkshire Police, which operates PNLD, did not respond to The Register's questions. So the campaign may combine portal misconfiguration with human-targeted access rather than relying on a single technique.
The common thread across every confirmed incident: no ransomware, no encryption, no malware. This is exfiltration and publication, full stop. Detection controls tuned for encryption events and payload execution will not see it.
What Organizations Should Do
- Audit every public-facing low-code portal now. If you run Microsoft Power Pages, Dataverse-backed sites, or any similar low-code front end, enumerate the tables each site exposes and verify table permissions for anonymous and authenticated web roles. Assume any table reachable without authentication is already public. This is the specific pattern VenariX flagged across the campaign.
- Inventory third-party and inter-system connections, not just applications. Newcastle's exposure was in a connection to an admissions system, not the admissions system itself. Integration endpoints, API connectors and data-sync links routinely fall outside both application security review and infrastructure scanning.
- Instrument for bulk read, not just for encryption. Build alerting on anomalous volumetric reads from database-backed portals and API endpoints: unusual row counts, unusual pagination behaviour, unusual source ASNs. A quiet 440,000-row read generates no ransomware telemetry at all.
- Treat helpdesk and service-desk staff as a priority phishing-resistance target. The DfE compromise reportedly began with social engineering against an internal helpdesk. Enforce out-of-band verification for account, access and data requests, and rehearse the specific scenario of a caller impersonating a partner institution.
- Warn affected populations before the criminals reach them. Applicants, students and staff whose contact details are in a published archive should be told directly to expect targeted phishing referencing real, accurate personal details, and told which channels your institution will and will not use for fees, offers and account changes.
- Prepare for record counts to move. Across this campaign, attacker claims and confirmed figures have diverged in both directions. Set expectations internally and with regulators that early attacker-sourced numbers are unverified, and distinguish records from individuals in every communication, as DfE did.
- Notify the regulator early and monitor the leak site. Newcastle, PNLD and DfE have all engaged the ICO. Where UK public sector or law enforcement data is involved, the NCA and NCSC are also in scope.
Sources: Newcastle University confirms data breach after ExfilSquad claims 4... | ExfilSquad hackers leak info of over 100,000 UK police officers, staff | Department for Education suffers data breach Computer Weekly | Police National Legal Database confirms data theft after dark web leak | Hackers publish details of 100k police staff on dark web | ExfilSquad: A New "Data extortion group” DarkOwl | ExfilSquad Leaks 135,000 UK Police Records as Investigators Report... | Exfilsquad Dumps 135,000 UK Police Records on Dark Web Alongside Ed...