VORANT. Threat Intelligence Sign in Get the full feed

Direwolf claims Arizona State University breach

high threat education

Ransomware group Direwolf lists Arizona State University as a victim, claiming exfiltration of employee, student and third-party credential data.

Ransomware.live tracking has recorded a new victim listing by the Direwolf ransomware group, naming Arizona State University (ASU) as a compromised target with an estimated attack date of August 17, 2026. The listing claims a substantial data exfiltration event affecting 1,477 employees and 13,204 users, along with 2,831 third-party employee credentials, indicating potential exposure of both internal staff and affiliated partner data.

The posting includes reconnaissance-style details such as DNS records, WHOIS data, and an inventory of third-party SaaS and cloud service integrations (Microsoft 365, Salesforce, Adobe, Cisco Duo, DocuSign, Box, and others), which may reflect the university's external attack surface rather than direct evidence of compromised systems. No specific initial access vector, ransomware payload details, or technical indicators of compromise were disclosed in the source listing. As with many entries on ransomware leak-site trackers, the claim originates from the threat actor's own disclosure and has not been independently verified by ASU or a third party at the time of this report.

The education sector remains a frequent target for ransomware operators due to large volumes of personal data, layered third-party vendor relationships, and often resource-constrained security teams. This incident, if confirmed, would represent a notable data exposure risk for a large public university, particularly given the scale of compromised employee and user credentials.

Mentioned in this report

Threat actors Dire Wolf
Malware Direwolf

Detection guidance

1 detection artefacts for this report are available to subscribers.

Source reporting: https://www.ransomware.live/id/QXJpem9uYSBTdGF0ZSBVbml2ZXJzaXR5IChBU1UpQGRpcmV3b2xm

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free