🇪🇬 Egypt - Mansoura University allegedly targeted in major data leak claim.
An underground forum actor claims to be selling and leaking data allegedly associated with Mansoura University, one of Egypt’s largest and oldest universities.
According to the threat actor, the alleged exposed data includes:
• Student records dating from 2012–2025/2026
• Usernames and names (Arabic and English)
• National ID numbers
• Email addresses
• Password-related fields
• Language, faculty, university, and course information
• Enrollment and academic status data
• Research documents and PDFs
• Internal university documents
• Student images/photos
The actor claims the leak contains:
• ~989,000 student records
• ~10GB+ total data volume
• Thousands of PDFs and internal images/documents
At this time:
• The claims remain unverified
• The authenticity and origin of the alleged dataset have not been independently confirmed
• No official public statement from Mansoura University regarding the claim has been observed
If authentic, the exposure could present significant risks involving:
• Identity theft and fraud
• Student-targeted phishing campaigns
• Credential stuffing attacks
• Academic document abuse
• Social engineering against students and faculty
• Potential misuse of national ID information
Educational institutions continue to face increasing cyber threats due to:
• Large centralized student databases
• Legacy infrastructure
• Broad user populations
• Extensive document storage systems
• High-value personal information repositories
Users associated with the university should remain cautious of:
• Emails requesting credential resets
• Fake academic portals
• Scholarship/payment scams
• SMS phishing and impersonation attempts
Daily Dark Web is continuing to monitor underground communities for additional samples, validation indicators, or official responses related to this claim.
#DDW #Intelligence #Egypt #CyberSecurity #DataLeak #DarkWeb #ThreatIntelligence #Education #University
🔍Threat Actor Profiling: Turla Group (aka Snake/Uroburos)🔍
I'm currently diving deep into the Turla Group, a highly advanced Russian-speaking cyber-espionage organization that's been active since at least 2004.
TURLA Group profiling report in the link:
https://t.co/3xVQxzPWyy
Regarding the recent so-called 'CrowdStrike' breach which was posted on BreachForum: this is not a data breach.
The individual responsible for the information ....disclosure, ...leak (?), operating under the moniker USDoD, openly states the data is scraped. Not sure why it's being labeled as a breach.
We briefly spoke with USDoD regarding it this afternoon. In summary, USDoD was able to programmatically abuse CrowdStrike endpoints to pull IOCs from CrowdStrike. The data pulled is proprietary, however this is the same information which is distributed to consumers.
According to USDoD scraping this data took quite a bit time (roughly a month), and the time the scrape operation completed it just so happened by chance to coincide with the recent CrowdStrike scandel – they've got bad luck it seems.
Photo courtesy of @FalconFeedsio