Cambridge University Press & Assessment hit by INC Ransom attack

Organization
Cambridge University Press & Assessment
Exploit
Ransomware
Industry
Publishing

Cambridge University Press & Assessment, the publishing and examinations arm of the University of Cambridge, confirmed in late June 2024 that it was dealing with technical disruption following a cybersecurity incident affecting part of its publishing operation.

The INC Ransom extortion group listed the organisation on its leak site and, on June 24, 2024, published documents it presented as evidence of the intrusion. Reporting on the listing described supplier invoices, service contracts and internal correspondence among the posted material.

The organisation said it had taken some systems offline as a precautionary measure while it worked to restore them, which left some staff temporarily without email access. It said the majority of its external customer-facing platforms were working as normal and that there had been no impact on the exam series then under way.

Cambridge University Press & Assessment said it was aware that a group had claimed data relating to the organisation had been published online, and that it was investigating with external IT and forensic specialists. The National Crime Agency led the investigation with support from the National Cyber Security Centre and other outside experts. The organisation said the work would take considerable time to complete, and did not put a figure on how many people or records were involved.

Sources