Ransomware victim disclosure
← All victimsNewcastle University
Claimed by ExfilSquad · listed 3 days ago
Status timeline
- ListedJul 26, 2026
- Data leakeddate unknown
At a glance
- Group
- ExfilSquad
- Status
- Data leaked
- Country
- United Kingdom
- Sector
- Education
- Listed on leak site
- Jul 26, 2026
About the victim
AI dossier — public-source company profileNewcastle University is a research-led institution ranked in the world's top 150, located in Newcastle, UK. The university offers undergraduate, postgraduate taught, and postgraduate research programmes across multiple faculties and campuses, including international sites in Malaysia and Singapore.
- Industry
- Higher Education & Research
- Address
- Newcastle, UK
- Employees
- 3000-5000
- Founded
- 1834
Attack summary
Severity: critical — Exfiltration and publication of 440K records containing student/applicant PII and contact information at a major UK university represents large-scale exposure of sensitive personal data affecting minors and adults. This constitutes a confirmed critical breach under GDPR and UK data protection law.ExfilSquad claims to have exfiltrated approximately 440,000 records containing applicant and student contact information, significant personally identifiable information (PII), and admissions data from Newcastle University. The group has published the data.
Data the group says was taken
AI dossier — extracted from the leak post- Student contact information
- Applicant contact information
- Personally identifiable information (PII)
- Admissions data
What the group claims
DATA SUMMARY: 440K~ records containing: applicant and student contact information, significant PII, and admissions data.
Sources
- Victim sitencl.ac.uk
Source
Indexed 3 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

