Newcastle University Confirms Data Breach as ExfilSquad Claims 440,000 Records — What Happened

Newcastle University Confirms Data Breach as ExfilSquad Claims 440,000 Records — What Happened

Newcastle University confirmed a data breach after unauthorized access leaked contact details from an admissions system. Here’s what was taken, who may be affected, and how to protect yourself online.

What Happened?

According to CyberInsider, Newcastle University confirmed a data breach linked to a configuration issue in one of its admissions systems.

The university was alerted to possible unauthorized access on July 27, 2026. It then began an investigation with outside security specialists.

The investigation found that the issue allowed unauthorized access to contact information stored in the university’s database.

Newcastle University corrected the configuration and says the unauthorized access is no longer ongoing. It also reported the incident to the UK Information Commissioner’s Office.

The university found no evidence of ransomware, malware, or a wider breach of its systems.

Meanwhile, the ExfilSquad cybercrime group says it stole about 440,000 records and published the information on its leak site. CyberInsider could not independently verify those files.

Even basic contact information can help criminals make phishing emails, texts, or calls look more convincing. And this risk is not limited to one university breach.

Your information may already have been leaked in another incident without you realizing it. If you are not sure, automatic monitoring can help you spot problems earlier. Futureproof monitors your data for leaks 24/7 and helps you reduce scam risks with simple, clear steps.

Who Was Affected and What Data Was Leaked?

Newcastle University has not publicly said how many people were affected.

ExfilSquad says it obtained around 440,000 records, but that number has not been independently confirmed.

According to the university, the information involved includes:

  • names
  • postal addresses
  • email addresses
  • telephone numbers

The university says passwords, financial information, admissions records, and exam results were not affected.

The information appears to involve people whose contact details were stored in the university’s admissions system, including applicants and students.

Even basic contact information can be useful to criminals. Your name, email, phone number, and address can make phishing messages or fake calls look more convincing.

How a Configuration Issue Allowed Access to University Data

Newcastle University says the breach involved a configuration issue affecting a connection to its admissions system.

A configuration issue simply means part of a system was set up incorrectly. In this case, the mistake allowed access that should not have been possible.

However, the university has not named the affected product or service. It has also not explained exactly which setting caused the problem.

The university says the issue has now been corrected.

Keep your personal information scam-proof

Futureproof keeps your data safer with simple guidance to set a strong password, turn on 2-step verification, and lock down your account.

Check my safety