Lancaster Uni data breach hits at least 12,500 wannabe students
.jpg)
Lancaster University - which offers a GCHQ-accredited degree in security - has been struck by a "sophisticated and malicious phishing attack" that resulted in the leak of around 12,500 wannabe students' personal data.
In a statement published yesterday evening, the university admitted that undergraduate applicant records for the years 2019 and 2020 had been accessed, along with the data of some current students.
Information accessed by whoever the hackers were - so far Lancaster has said nothing about this - includes names, addresses, phone numbers and email addresses.
The uni also mentioned fraudulent invoices "had been sent to some undergraduate applicants".
Lancaster accepted 3,585 applicants for student places in the educational year 2018, the latest for which data is available. Over the past five years, the number of people accepted onto courses increased by around 100 to 200 people per year, meaning the latest data breach is likely to have affected around 3,700 successful applicants.
Of the 3,585 students accepted by Lancaster last year, 375 were from other EU countries and 575 were from non-EU nations.
Further statistics compiled by UCAS show that 12,545 people applied to Lancaster in 2018 alone, with the number having been roughly stable for the preceding three years. On that basis, the recent data breach may have affected about 12,500 applicants.
No data is available from public sources on the number of non-EU applicants to Lancaster.
UCAS told The Register that these numbers do not include those who applied through Clearing, the process where wannabe students desperate to get on any degree course at all are matched up with empty places on under-subscribed courses.
"We acted as soon as we became aware that Lancaster was the source of the breach on Friday and established an incident team to handle the situation. It was immediately reported to the Information Commissioner's Office," said the university in a prepared statement.
We understand the university's graduation week took place just last week. With A-level final results being published in a few weeks from now, the timing is rather bad. Ironically, Lancaster offers a master's degree in cyber security – accredited by none other than GCHQ. El Reg trusts the intrusion wasn't caused by students putting their newly learned skills to the test.
The university did not answer The Register's questions about how many people were affected by the breach, claiming that a police investigation means it is bound by some sort of code of omerta. This "blame the cops" strategy is a relatively common one for deflecting bad PR and attempting to minimise the impact of a data breach.
In the academic year 2017-18, the most recent year for which official statistics are available, the university had 14,210 enrolled students.
source theregister
Industry: Cyber Security

Latest Jobs
-
- Senior Presales Consultant | Managed Security Services | London
- London
- N/A
-
Senior Presales Consultant – Managed Security Services Location: London-commutable (Hybrid) A well-established cyber consultancy is seeking a Senior Presales Consultant to drive growth across its managed security services / advisory portfolio. This hybrid role bridges commercial and technical expertise supporting solution design, shaping customer proposals, and guiding conversations from scoping through to delivery. Key experience: Background in managed security services, including SOC operations and threat detection Strong knowledge of cloud and on-prem security tooling (SIEM, EDR, IAM) Penetration testing Proven ability to translate technical concepts into clear business value Confident in customer-facing engagements and pre-sales delivery Experience contributing to bids, proposals, and RFI/RFP responses To find out more contact me on 07884666351 Visa sponsorship is unfortunately not available for this role.
-
- Senior SOC Engineer - Microsoft | Splunk. Permanent. London
- London
- N/A
-
Senior SOC Engineer – Hybrid London Type: Full-Time A well-established cyber security provider is seeking a Senior SOC Engineer to strengthen its managed services function. This role is ideal for someone with a strong operational background in SIEM and EDR tools who can confidently lead customer onboarding, fine-tune detection strategies, and act as a senior point of contact for technical escalations. You will need to be SC clearable. Bonus points if you have SC clearance currently. You will be responsible for ensuring smooth integration of new clients into the service, optimising alerting capabilities and delivering meaningful outcomes during investigations. This is a hands-on position, working closely with internal teams and external stakeholders to maintain robust security operations across multiple environments. Prior experience in a cyber-focused MSP or MSSP Strong hands-on capability with platforms such as Microsoft Sentinel, Defender for Endpoint, or similar Proficiency in scripting and query languages such as KQL or PowerShell Knowledge of detection logic, investigation workflows, and cloud-based infrastructure Confident communicator with strong documentation and reporting skills Apply today for more information.
-
- New Business | Cyber Security | Overlay sales (UK Based- London commutable)
- London
- N/A
-
New Business Sales Hunter needed | Cybersecurity (UK Based- London commutable) Are you looking for uncapped commission, a fun and sociable team that drives success with no politics? If so...You must Have a demonstrable history of sales success in Cyber Security Follow Weatons law. The role: Seeking a proven New Business Sales Hunter to join an established, successful and expanding team. New business focused - £500-750 GP Sell a blend of security services & professional services. Ideal experience selling some or all of the following Cyber strategy & risk management Managed detection & response (MDR) Penetration testing Compliance & audit support You: Strong cybersecurity/IT services sales track record. Confident selling into mid-market & enterprise. UK based - London commutable Hunter mindset, full sales cycle ownership. Don't just send an email to apply give me a call on 07884666351
-
- Service Architect- DACH regions
- Germany
- Upto €110,000 plus bonus and benefits
-
Lead Service Architect with the authority and experience to take control of complex, multi-million-euro outsourcing bids. This role is about leading the Service/ solutioning effort, bringing structure to chaos, and driving the entire bid team to deliver winning proposals. The company area a global managed services business working with enterprise and public sector clients, across Cloud, End-User Computing, Digital Workplace, Service Desk, and Network Infrastructure. What You’ll Do: Lead Service/ solution design from qualification to contract. Control bid teams — architects, pricing, delivery, and SMEs. Break down RFPs/RFIs into actionable, costed, client-ready solutions. Present internally and to clients at decision-maker level. Run solution workshops, own the architecture, and shape the financial model. You’ll Need: Experience working as a Service architect, Service Manager or Customer Success Manager R Gravitas to lead and drive teams through high-stakes bids. Deep knowledge of managed services delivery and commercial models. Strong technical grasp: Cloud, Security, EUC, Unified Comms, Service Desk, and more. Experience leading deals across onshore, offshore, and hybrid delivery models.