Newcastle University confirmed a data breach after unauthorized access leaked contact details from an admissions system. Here’s what was taken, who may be affected, and how to protect yourself online.
Table of Contents
What Happened?
The university was alerted to possible unauthorized access on July 27, 2026. It then began an investigation with outside security specialists.
The investigation found that the issue allowed unauthorized access to contact information stored in the university’s database.
Newcastle University corrected the configuration and says the unauthorized access is no longer ongoing. It also reported the incident to the UK Information Commissioner’s Office.
The university found no evidence of ransomware, malware, or a wider breach of its systems.
Meanwhile, the ExfilSquad cybercrime group says it stole about 440,000 records and published the information on its leak site. CyberInsider could not independently verify those files.
Even basic contact information can help criminals make phishing emails, texts, or calls look more convincing. And this risk is not limited to one university breach.
Your information may already have been leaked in another incident without you realizing it. If you are not sure, automatic monitoring can help you spot problems earlier. Futureproof monitors your data for leaks 24/7 and helps you reduce scam risks with simple, clear steps.
Who Was Affected and What Data Was Leaked?
Newcastle University has not publicly said how many people were affected.
ExfilSquad says it obtained around 440,000 records, but that number has not been independently confirmed.
According to the university, the information involved includes:
- names
- postal addresses
- email addresses
- telephone numbers
The university says passwords, financial information, admissions records, and exam results were not affected.
The information appears to involve people whose contact details were stored in the university’s admissions system, including applicants and students.
Even basic contact information can be useful to criminals. Your name, email, phone number, and address can make phishing messages or fake calls look more convincing.
How a Configuration Issue Allowed Access to University Data
Newcastle University says the breach involved a configuration issue affecting a connection to its admissions system.
A configuration issue simply means part of a system was set up incorrectly. In this case, the mistake allowed access that should not have been possible.
However, the university has not named the affected product or service. It has also not explained exactly which setting caused the problem.
The university says the issue has now been corrected.
Futureproof keeps your data safer with simple guidance to set a strong password, turn on 2-step verification, and lock down your account.
Check my safety
At Futureproof, Kevin explains digital safety in simple words, with clear tips and zero fluff. He holds a degree in information technology and studies fraud trends to keep his tips up-to-date.
In his free time, Kevin plays with his cat, enjoys board-game nights, and hunts for New York’s best cinnamon rolls.
