Skip to content
NetarxImpact Database
Credential Phishing PortalNo AI reportedConfirmed

Lancaster University phishing breach exposes 12,500 applicants, then fake invoices follow

Lancaster University · Education · United Kingdom · July 2019

People or records affected
12,500
13K as reported

What happened

Lancaster University disclosed on 22 July 2019 that a sophisticated and malicious phishing attack had exposed the records of around 12,500 undergraduate applicants for 2019 and 2020, along with some current student data. Exposed fields included names, addresses, telephone numbers and email addresses. Fraudulent invoices were subsequently sent to some applicants using the stolen details. Police arrested a suspect within days.

How the deception worked

Phishing against university staff yielded access to the applicant records system. What made this breach unusual is the immediate monetisation: rather than selling the data, the attacker used it to send fraudulent invoices directly to undergraduate applicants. Those recipients were the ideal targets, because a prospective student who has just applied is expecting communication from the university about fees and accommodation, and has no baseline for what a genuine invoice looks like. The stolen contact details supplied exactly the personalisation, real name, real address, real course application, that makes a fake bill credible. The university reported to the ICO and warned applicants directly.

The control that would have caught it· our reading, not a claim from the sources

Multi-factor authentication on staff accounts, plus a published policy that the university never invoices applicants by email, closes both the intrusion and the downstream fraud.

Sources (2)

  1. Lancaster University Confirms Data Breach, Applicants Targeted
    Infosecurity Magazine·infosecurity-magazine.comOpen ↗
  2. Lancaster University data breach
    The Register·theregister.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.