~/f4n6 $ grep -r "Ransomware: ExfilSquad named Newcastle University (GB)" ./investigations/ --include="*.md"

Ransomware: ExfilSquad named Newcastle University (GB)

Jeff Davies 26 Jul 2026 3 min read

1. Executive summary

On 2026-07-26, the actor "ExfilSquad" publicly claimed a ransomware attack against Newcastle University (GB), posting on their leak site that they exfiltrated approximately 440,000 records containing applicant and student contact information, significant PII, and admissions data. Attribution to ExfilSquad is unconfirmed: the actor has no MITRE ATT&CK profile in the verified reference data, and the claim rests on a single source (ransomware.live). No CISA-KEV exploitation state, CVSS score, or specific CVE is associated with this item. EMEA financial services clients are unlikely to be direct victims, but should assess third-party and supply-chain exposure to Newcastle University and treat the PII disclosure as a potential downstream fraud vector.

2. Regulatory framing

No specific DORA/NIS2 article is directly engaged by this item. The incident occurred at a UK university, not a regulated financial entity or ICT third-party provider to the financial sector. Unless a client has a direct contractual or data-sharing relationship with Newcastle University that triggers incident classification or third-party risk obligations, the DORA and NIS2 articles in scope do not apply to this specific event.

3. Technical analysis & attack chain

The source material is a ransomware leak-site posting aggregated by ransomware.live. It provides victim metadata and a data summary but no technical attack-chain detail. The following is confirmed from the source:

  1. Actor claim: ExfilSquad posted Newcastle University as a victim on their leak site on 2026-07-26.
  2. Data exfiltrated: ~440,000 records containing applicant and student contact information, significant PII, and admissions data.
  3. Victim context: ransomware.live reports 192 compromised employees, 1,799 compromised users, 78 third-party employee credentials, and 121 external attack-surface entries associated with the victim's domain (ncl.ac.uk). These figures are sourced via Hudson Rock and represent infostealer-compromised credentials and attack-surface data — they are contextual, not confirmation of the specific attack vector.

What is NOT confirmed

  • Initial access vector, exploited vulnerability or CVE, malware payload, persistence mechanism, C2 infrastructure, lateral movement technique, and encryption behaviour are all absent from the source.
  • Whether this is a double-extortion (exfiltration + encryption) event or exfiltration-only is not stated. The source describes data theft but does not confirm ransomware deployment on victim systems.
  • Attribution to ExfilSquad is unconfirmed (no MITRE ATT&CK profile in verified reference data). The claim is single-sourced via ransomware.live; verify before enforcement.

4. Mitigation & containment

This is a third-party exposure event for EMEA financial services clients, not a direct compromise. Actions are prioritised accordingly.

P1 — within 24h

  • Check vendor and third-party risk registers for any active relationship with Newcastle University (ncl.ac.uk). If a relationship exists, confirm whether any client data is shared, hosted, or processed by the university.
  • Block the domain ncl.ac.uk on outbound mail gateways if there is no legitimate business relationship, to reduce risk of credential-phishing using university-themed lites built from the disclosed PII.

P2 — within 72h

  • If a data-sharing or research partnership exists, request an incident notification from Newcastle University's security team. Assess whether any client PII or intellectual property is in the exfiltrated dataset.
  • Review authentication logs for any client accounts that use ncl.ac.uk email addresses as contact or recovery addresses. Force password reset and MFA re-enrolment where matches are found.
  • Alert fraud operations teams to the 440K-record PII dataset. Applicant and admissions data typically includes names, dates of birth, addresses, and national identifiers — sufficient for social-engineering and account-takeover attempts targeting customers.

P3 — within 7 days

  • If Newcastle University is a registered ICT third-party provider, review contractual incident-notification clauses and document the event in the third-party risk register.
  • Monitor the ransomware.live page and ExfilSquad channels for confirmation of data publication or additional claims.

5. Indicators of compromise

No indicators of compromise available in the source material. The source provides victim metadata and data-volume claims but no atomic IOCs (no hashes, IPs, domains, URLs, email addresses, or file artefacts associated with the attacker).

Behavioural indicators

Behaviour Where to observe Confidence
Infostealer-compromised credentials for ncl.ac.uk (192 employees, 1,799 users per Hudson Rock data) Infostealer intelligence platforms / dark-web credential feeds Low — contextual to victim, not confirmed as attack vector
78 third-party employee credentials associated with the victim Infostealer intelligence platforms Low — contextual; may indicate credential-based initial access path
Social-engineering attempts using exfiltrated applicant/student PII (names, DOB, addresses, admissions data) Customer fraud monitoring, SOC social-engineering alert queues Medium — expected post-disclosure abuse pattern, not yet observed

6. Detection

Insufficient indicators to author detection rules. The source contains no malware strings, file names, registry keys, command-line artefacts, mutex names, network indicators, or ransom-note text associated with the threat actor or payload.

7. Sources

  • Ransomware.live, "Victim: Newcastle University – ExfilSquad," https://www.ransomware.live/id/TmV3Y2FzdGxlIFVuaXZlcnNpdHlARXhmaWxTcXVhZA==, published 2026-07-26.

8. Adverse Trace position

This is a single-sourced ransomware claim with no technical attack-chain detail and unconfirmed actor attribution (ExfilSquad has no MITRE ATT&CK profile). The direct risk to EMEA financial services clients is low unless they have a data-sharing or contractual relationship with Newcastle University. The 440K-record PII disclosure is the primary downstream risk — applicant and admissions data is high-value material for social-engineering and synthetic-identity fraud targeting financial institutions. We are treating this as a watch-and-monitor item: we will track ExfilSquad for corroboration, additional victims in the financial sector, and any publication of the exfiltrated dataset. Clients with active relationships to Newcastle University should escalate to P1 actions immediately.


Read the original source →

Published via PulseTrace — Adverse Trace threat intelligence.

Post this to LinkedIn
Formatting is converted automatically — headings, bullets, a link back & hashtags. Paste straight in.
J
Jeff Davies