Ransomware victim disclosure
← All victimsArizona State University (ASU)
Claimed by Direwolf · listed 11 hours ago
Status timeline
- ListedAug 17, 2026
- Data leakeddate unknown
At a glance
- Group
- Direwolf
- Status
- Data leaked
- Country
- United States
- Sector
- Education
- Listed on leak site
- Aug 17, 2026
About the victim
AI dossier — public-source company profileArizona State University (ASU) is a comprehensive public research university with over 200,000 students enrolled across multiple campuses. It operates through three main enterprises: Academic Enterprise (traditional degree programs), Knowledge Enterprise (research and innovation), and Learning Enterprise (online and lifelong learning programs including EdPlus and CareerCatalyst). ASU is one of the largest public universities in the US.
- Industry
- Higher Education & Public Research University
- Address
- Tempe, Arizona, US (main campus)
- Employees
- 10000-15000
- Founded
- 1885
Attack summary
Severity: critical — Confirmed exfiltration of sensitive personally identifiable information at massive scale (680K+ student/learner contacts, 383K user accounts, payment records, identity verification data, educational records), combined with financial/payment data (826K payment transactions, PayPal ledgers) and authentication credentials (OAuth tokens, ASURITE usernames). This meets the threshold for critical due to regulated educational data, scale of exposure, and financial/payment system compromise.The direwolf group claims to have exfiltrated 4.74 GB of data spanning 7,925 files, 4 databases, and ~5.5 million rows from ASU's Learning Enterprise and EdPlus platforms. The breach includes Salesforce CRM records (3.3M rows), DynamoDB backend systems (1.8M rows), Canvas LMS user directory (383K users), and Dropbox team files (3.72 GB), covering the period March 2017 through August 2026.
Data the group says was taken
AI dossier — extracted from the leak post- Payment transaction records (826K)
- Learner/student contact records and profiles (680K+)
- User directory with authentication credentials (383K Canvas LMS users)
- PayPal invoice ledger and payment processing logs (195K)
- Identity verification records for learners (127K)
- Admin audit trails and activity logs (59K)
- Partner invoicing and vendor contracts (4.3K files)
- ASURITE ID and affiliate onboarding rosters (3K files)
- Grade report exports and academic records (30K+)
- User email mappings and OAuth tokens
What the group claims
Colleges,Universities
The leak post
captured from the group's site```
{"article":{"id":91,"title":"Arizona State University (ASU)","content":"\u003ch2\u003e1. Overview\u003c/h2\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eItem\u003c/th\u003e\n\u003cth\u003eValue\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003eBusiness\u003c/td\u003e\n\u003ctd\u003e\u003cstrong\u003eArizona State University — Learning Enterprise / EdPlus\u003c/strong\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eTotal size\u003c/td\u003e\n\u003ctd\u003e\u003cstrong\u003e4.74 GB, 7,925 files/tables, 4 databases, ~5.5 million rows\u003c/strong\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eTime range\u003c/td\u003e\n\u003ctd\u003e\u003cstrong\u003e2017-03 ~ 2026-08\u003c/strong\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch2\u003e2. Database Inventory\u003c/h2\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eDatabase\u003c/th\u003e\n\u003cth\u003eEngine\u003c/th\u003e\n\u003cth\u003eTables\u003c/th\u003e\n\u003cth\u003eRows\u003c/th\u003e\n\u003cth\u003eSize\u003c/th\u003e\n\u003cth\u003eCon…Sources
Source
Indexed 11 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

