# Direwolf claims Arizona State University breach

Published: 2026-08-17 · Severity: high · Sectors: education
Canonical: https://vorant.io/reports/eb5ac976-9a27-5dec-a085-d76836115058/direwolf-claims-arizona-state-university-breach

> Ransomware group Direwolf lists Arizona State University as a victim, claiming exfiltration of employee, student and third-party credential data.

Ransomware.live tracking has recorded a new victim listing by the Direwolf ransomware group, naming Arizona State University (ASU) as a compromised target with an estimated attack date of August 17, 2026. The listing claims a substantial data exfiltration event affecting 1,477 employees and 13,204 users, along with 2,831 third-party employee credentials, indicating potential exposure of both internal staff and affiliated partner data.

The posting includes reconnaissance-style details such as DNS records, WHOIS data, and an inventory of third-party SaaS and cloud service integrations (Microsoft 365, Salesforce, Adobe, Cisco Duo, DocuSign, Box, and others), which may reflect the university's external attack surface rather than direct evidence of compromised systems. No specific initial access vector, ransomware payload details, or technical indicators of compromise were disclosed in the source listing. As with many entries on ransomware leak-site trackers, the claim originates from the threat actor's own disclosure and has not been independently verified by ASU or a third party at the time of this report.

The education sector remains a frequent target for ransomware operators due to large volumes of personal data, layered third-party vendor relationships, and often resource-constrained security teams. This incident, if confirmed, would represent a notable data exposure risk for a large public university, particularly given the scale of compromised employee and user credentials.

## Mentioned in this report

- Threat actors: Dire Wolf
- Malware: Direwolf

1 more detection artefacts for this report (IOC-atomic rules, Splunk/KQL/Elastic conversions, YARA, Suricata) are available to subscribers.

Source reporting: https://www.ransomware.live/id/QXJpem9uYSBTdGF0ZSBVbml2ZXJzaXR5IChBU1UpQGRpcmV3b2xm

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/eb5ac976-9a27-5dec-a085-d76836115058/direwolf-claims-arizona-state-university-breach.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
