Menu
Browse
Date:

Jun 2024

Location:

United Kingdom

Summary

Cambridge University Press & Assessment experienced a cybersecurity incident involving technical disruptions and temporary email access loss for employees, following an attack claimed by the INC Ransomware group. The attackers employed double extortion tactics, stealing and encrypting sensitive documents including supplier invoices and service contracts before threatening public release. While some systems were taken offline as a precaution, most customer-facing platforms remained operational with no impact on ongoing exams. The organization engaged external IT and forensic experts, collaborating with authorities like the UK's National Cyber Security Centre to investigate the breach and restore access. This incident follows multiple unrelated cyber attacks affecting other Cambridge University entities in recent months.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

Cambridge University Press & Assessment (CUPA) experienced a cybersecurity incident impacting its publishing operations, first publicly acknowledged in a statement on June 27, 2024. The organization reported "technical disruption" affecting employee systems, including a temporary loss of email access for some staff. CUPA confirmed taking precautionary measures by shutting down certain systems upon discovering the incident and engaging external IT and forensic specialists to investigate. The cybercriminal group INC Ransomware claimed responsibility for the attack, publishing stolen documents on its disclosure page on June 24 as proof of compromise. These documents included supplier invoices, service contracts, and confidential correspondence obtained through unauthorized access.

Cyber Incident Image

The incident caused operational disruptions but did not affect external customer-facing platforms or the ongoing exam series. INC Ransomware, active since August 2023, employed double extortion tactics by both encrypting data and threatening public release of stolen information unless ransom demands were met. CUPA collaborated with the UK’s National Cyber Security Centre and other authorities to investigate the data publication claims while working to restore affected systems. This attack followed separate cybersecurity incidents targeting Cambridge University’s Medical School, University Library, and central servers in preceding months, though no confirmed connection exists between these events. Forensic experts advised the investigation would require significant time, with CUPA committing to provide updates to stakeholders as progress continues. Restoration efforts prioritized email access recovery, with the organization reporting "good progress" in reinstating services despite ongoing system limitations.

Sources
Sources available to members
1 source