{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2019-lancaster-university-phishing-breach-exposes-12-500-applicants-then-fake"},"incident":{"slug":"2019-lancaster-university-phishing-breach-exposes-12-500-applicants-then-fake","title":"Lancaster University phishing breach exposes 12,500 applicants, then fake invoices follow","date":"2019-07","date_precision":"month","year":2019,"victim_org":"Lancaster University","sector":"Education","country":"United Kingdom","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Credential Theft","Wire Fraud / Financial Loss"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":12500,"threat_actor":null,"summary":"Lancaster University disclosed on 22 July 2019 that a sophisticated and malicious phishing attack had exposed the records of around 12,500 undergraduate applicants for 2019 and 2020, along with some current student data. Exposed fields included names, addresses, telephone numbers and email addresses. Fraudulent invoices were subsequently sent to some applicants using the stolen details. Police arrested a suspect within days.","how_it_worked":"Phishing against university staff yielded access to the applicant records system. What made this breach unusual is the immediate monetisation: rather than selling the data, the attacker used it to send fraudulent invoices directly to undergraduate applicants. Those recipients were the ideal targets, because a prospective student who has just applied is expecting communication from the university about fees and accommodation, and has no baseline for what a genuine invoice looks like. The stolen contact details supplied exactly the personalisation, real name, real address, real course application, that makes a fake bill credible. The university reported to the ICO and warned applicants directly.","lessons":"Multi-factor authentication on staff accounts, plus a published policy that the university never invoices applicants by email, closes both the intrusion and the downstream fraud.","confidence":"Confirmed","sources":[{"title":"Lancaster University Confirms Data Breach, Applicants Targeted","url":"https://www.infosecurity-magazine.com/news/lancaster-university-breach/","publisher":"Infosecurity Magazine"},{"title":"Lancaster University data breach","url":"https://www.theregister.com/2019/07/23/lancaster_university_data_breach/","publisher":"The Register"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2019-lancaster-university-phishing-breach-exposes-12-500-applicants-then-fake"}}