CSIDB logo
Incident

Northern Caribbean University

Incident posture

Attack window
Feb 2025
Location
Jamaica
Status
Ongoing
CIA posture
Available to members
Updated
2026-09-02 11:52

Linked entities

Victim
Northern Caribbean University
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Feb 2025
Discovered
Undetermined
Disclosed
Feb 2025
Resolved
Pending

Summary

A major cyberattack crippled key computer systems at the Manchester-based university, rendering the Learning Management System inoperable and leaving university records and student financial databases inaccessible. Although there was no indication that personal information had been made public, the administration alerted current and former students about the possibility that data could be released. The institution's website was taken down, while social media platforms and email systems remained operational. A multi-agency response was triggered, with reports filed to the Jamaica Cyber Incident Response Team, the Office of the Information Commissioner, and the Major Organised Crime and Anti-Corruption Agency. Staff were required to continue working as usual, and there was no timeline for restoring normal operations.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

Northern Caribbean University (NCU), a Manchester-based higher education institution in Jamaica, experienced a significant cyberattack that occurred on a Saturday and was publicly disclosed through a statement issued by the university administration on the following Monday evening. The incident had a substantial impact on the university's information technology infrastructure, crippling key computer systems and rendering critical databases inaccessible. Specifically, the attack affected university records and student financial databases, both of which became unavailable to staff and students in the immediate aftermath of the event. The university acknowledged in its public statement that although there was no indication at that point that information about current and former students had been made public, the administration was alerting these stakeholders to the possibility that personal data could be released to the public by the cyberattackers. This warning reflected the administration's recognition of the potential scope of the breach and the sensitivity of the information held within the affected systems.

The operational consequences of the attack were felt across multiple facets of university life. The Learning Management System was rendered inoperable, disrupting the standard digital environment in which students and lecturers typically conducted coursework, assignments, and instructional activities. As a result, students and lecturers were forced to use alternative platforms to continue their academic work while the primary system remained offline. The university's official website was also taken down as a consequence of the incident, limiting the institution's ability to communicate through its primary web presence. Despite these disruptions, the university noted that its social media platforms and email system remained operational, providing channels through which the administration could continue to communicate with stakeholders and through which the broader public could be informed about developments. Staff members were instructed to continue working as usual unless they received specific alternative directions from their supervisors, indicating an effort to maintain administrative continuity despite the technological challenges. At the time of the initial disclosure, the university did not provide a timeline for when normal operations would be fully restored, leaving the duration of the disruption uncertain.

In response to the attack, NCU initiated a multi-agency response, filing reports with several Jamaican governmental and law enforcement bodies. These included the Jamaica Cyber Incident Response Team, which serves as the national coordinator for cyber incident handling; the Office of the Information Commissioner, which oversees matters relating to data protection and information rights; and the Major Organised Crime and Anti-Corruption Agency, which investigates serious organized criminal activity. The involvement of these agencies indicates the seriousness with which the incident was treated and the multi-jurisdictional and multi-disciplinary nature of the response. The university also alerted current and former students directly about the possibility that their personal data could be exposed, fulfilling an apparent duty to inform affected stakeholders even in the absence of confirmed data publication.

The cyberattack against NCU was not the first such incident the institution had experienced. In January 2022, NCU was previously hit by ransomware, a type of malicious software that encrypts files on a device and renders affected files and systems unusable. The recurrence of a major cyberattack at the same institution within a span of approximately three years highlights an ongoing pattern of targeting and underscores the persistent cybersecurity challenges facing the university. While the source material does not specify the particular type of malware, the method, or the actors responsible for the more recent incident, the prior occurrence of ransomware establishes a relevant historical context for understanding the vulnerability of the institution's systems.

Sources

Sources available to members: 1 source.

CSIDB