Hackers hold Newcastle Uni student data to ransom
DoppelPaymer group is threatening to release more data online unless the university pays out


Newcastle University is being held to ransom after cyber criminals hacked into its systems at the start of September.
The group behind the attack are known as 'DoppelPaymer' and have been previously linked to an attack on Elon Musk's companies SpaceX and Tesla.
The attack on the university was reported as a "cyber incident" which shutdown a number of its IT systems and took place on 4 September. At around 10:00 that same day, a backup file was taken, the university said.
The criminals have posted some of this data, which concerns students and staff members, on the dark web, according to the group's Twitter page, with a threat of more to come if they don't pay the ransom.
"Dear students of the New Castle University Congratulations with an upcoming release of your personal data," the tweet read. "What a great start of a new educational year #doppelpaymer #ransomware #malware #doppleleaks"
The university said it had alerted the Information Commissioner's Office and the police. According to its website, it could take "several weeks" to address its IT issues. As such, many services will remain offline. Third-party security experts have been drafted in, the university confirmed, and an investigation into the attack and the extent of the damage is underway.
The attack on Newcastle University follows another on Northumbria University, which had to cancel exams and shutdown its clearing hotline due to IT disruption. Although the method of attack wasn't specified in the Northumbria case, Newcastle has been reportedly hit with ransomware, which is becoming increasingly common for universities in 2020.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
The DoppelPaymer group are said to also offer their services for others to use, similar to the 'ransomware as a service' (RaaS) operation run by the Netwalker group, which has reportedly made over $29 million since March.
Bobby Hellard is ITPro's Reviews Editor and has worked on CloudPro and ChannelPro since 2018. In his time at ITPro, Bobby has covered stories for all the major technology companies, such as Apple, Microsoft, Amazon and Facebook, and regularly attends industry-leading events such as AWS Re:Invent and Google Cloud Next.
Bobby mainly covers hardware reviews, but you will also recognize him as the face of many of our video reviews of laptops and smartphones.
-
Prolific ransomware operator added to Europe’s Most Wanted list as US dangles $10 million reward
News The US Department of Justice is offering a reward of up to $10 million for information leading to the arrest of Volodymyr Viktorovych Tymoshchuk, an alleged ransomware criminal.
-
Jaguar Land Rover “did the right thing” shutting down systems to thwart cyber attack
News The attack on Jaguar Land Rover highlights the growing attractiveness of the automotive sector
-
Ransomware attack on IT supplier disrupts hundreds of Swedish municipalities
News The attack on IT systems supplier Miljödata has impacted public sector services across the country
-
A notorious hacker group is ramping up cloud-based ransomware attacks
News The Storm-0501 threat group is refining its tactics, according to Microsoft, shifting away from traditional endpoint-based attacks and toward cloud-based ransomware.
-
Security researchers have just identified what could be the first ‘AI-powered’ ransomware strain – and it uses OpenAI’s gpt-oss-20b model
News Using OpenAI's gpt-oss:20b model, ‘PromptLock’ generates malicious Lua scripts via the Ollama API.
-
Data I/O shuts down systems in wake of ransomware attack
News Regulatory filings by Data I/O suggest the costs of dealing with the attack could be significant
-
Average ransom payment doubles in a single quarter
News Targeted social engineering and data exfiltration have become the biggest tactics as three major ransomware groups dominate
-
BlackSuit ransomware gang taken down in latest law enforcement sting – but members have already formed a new group
News The notorious gang has seen its servers taken down and bitcoin seized, but may have morphed into a new group called Chaos