CSIDB logo
Incident

Newcastle University

Incident posture

Attack window
Jul 2017
Location
United Kingdom
Status
Historical
CIA posture
Available to members
Updated
2025-12-01 00:00

Linked entities

Victim
Newcastle University
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jul 2017
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Newcastle University warned prospective students about a fraudulent website impersonating its official domain to deceive applicants, particularly targeting foreign students with sophisticated branding mimicking the institution's colors and fonts. The fake site, newcastleinternationaluniversity.com, featured elaborate animations and a professional layout to harvest sensitive personal data including credit card details, passport information, and birthdates, enabling both financial fraud and identity theft. The university confirmed no affiliation with the fraudulent platform and directed applicants to its legitimate website while advising against submitting personal details to the scam operation.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

In July 2017, Newcastle University identified a fraudulent website impersonating its official domain (ncl.ac.uk) to deceive prospective students. The phishing site, operating under the domain newcastleinternationaluniversity.com, replicated the university’s branding elements—including colors and fonts—while incorporating flashy animations and a more polished layout than the legitimate site. This imitation targeted international applicants, particularly those unfamiliar with the authentic web presence, by presenting itself as a credible platform for course applications and tuition payments. The fraudulent site collected sensitive personal information including credit card details, passport numbers, and dates of birth—data that could enable both immediate financial theft and long-term identity fraud. The university confirmed the site had no affiliation with its operations but noted its sophisticated design increased the risk of victims mistaking it for a legitimate portal.

Newcastle University responded by issuing a public alert via Twitter on July 20, 2017, explicitly disavowing any connection to the fraudulent domain and urging applicants to avoid submitting personal or payment details. The institution directed all users to its official website (ncl.ac.uk) for secure transactions. While the exact number of affected individuals remained unknown, the university emphasized the severity of the threat due to the site’s capability to harvest comprehensive identity data alongside tuition payments. Security firm RSA separately advised general precautions against phishing, such as verifying URLs and avoiding email links, though their involvement in the specific incident was not detailed. The incident highlighted risks to international students and underscored the potential for financial and reputational harm to both victims and the institution.

Sources

Sources available to members: 1 source.

CSIDB