CSIDB logo
Threat actor

SCUWatch

Attribution profile

Type
Activist
Location
United States of America
Known incidents
1 incident
First seen
2016-10-17
Last seen
2016-10-17
Updated
2026-07-30 21:51
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

SCUWatch is an alias used by a threat actor that has been publicly linked to a single documented incident targeting the Office of Marketing and Communications at Santa Clara University in the United States of America. The actor identifies itself solely by the name SCUWatch and has not been associated with any other aliases, geographic bases, or organizational affiliations in open sources. The known activity focuses on the education sector within the United States, specifically exploiting perceived weaknesses in password management at a private university. The actor’s stated purpose, as communicated to the campus newspaper that received the leaked material, was to highlight inadequate password security practices rather than to pursue financial gain, espionage, or overt disruption.

The only technique explicitly referenced in the reporting is the exploitation of weak or careless password controls to gain unauthorized access to internal documents; no malware families, exploit kits, or specialized tooling are mentioned in the source material. After obtaining the files, SCUWatch transmitted the stolen data via email to a university newspaper, attaching a folder labeled “OMC_Leak” that contained crisis management plans, social media strategy documents, and personal contact information for senior administrators. This method of exfiltration relies on straightforward electronic mail rather than covert channels or advanced persistence mechanisms, and the actor did not employ any known malware or custom frameworks during the operation.

The sole publicly reported operation attributed to SCUWatch occurred on October 17 2016, when the actor leaked internal records from Santa Clara University’s Office of Marketing and Communications. The incident was covered by a data‑breach news outlet and the campus newspaper, which quoted the actor’s explanation that the compromise stemmed from poor password hygiene rather than a technical breach of network defenses. No additional campaigns, associated malware, or connections to state sponsors or criminal consortia have been documented in the available sources, leaving the actor’s broader affiliations and subsequent activities undetermined.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB