Skip to Content

Ransomware Hits the University of Cambridge's Publisher

Cambridge's publishing and assessment arm had documents leaked in a double-extortion attack. A lesson on protecting business data.
June 26, 2026 by
Ransomware Hits the University of Cambridge's Publisher
Kleber Leal by Zamak Portal

In June 2024, Cambridge University Press & Assessment — the publishing and assessment arm of the University of Cambridge — was targeted by the ransomware group INC Ransomware, which operates through double extortion: in addition to compromising systems, it steals data and threatens to publish it if the ransom is not paid. As a precautionary measure, part of the systems were shut down, as reported by Times Higher Education and by GÉANT Security.

By the end of June, the group published internal documents on its leak site as proof of the attack — supplier invoices, service contracts, and confidential correspondence. This was not a customer database, but exactly the kind of business document that any company accumulates on a daily basis and rarely protects with the same care given to production systems.

That is where the lesson lies for any manager. The most serious damage doesn't always come from the customer database: it comes from contracts, proposals, invoices, and emails that, when exposed, create legal, commercial, and reputational vulnerabilities. And in double extortion, having a backup is not enough — the problem is no longer about "getting back up and running" but about "these documents cannot become public."

Does your company know where its contracts and sensitive data are — and who can access them?

Reducing this risk starts with visibility and data classification: knowing where critical documents live, restricting access to the minimum necessary, enforcing multi-factor authentication, and monitoring with 24/7 detection and response to contain the attacker before exfiltration. Combined with isolated backups and a rehearsed incident response plan, this turns a potentially devastating leak into a contained incident. Protecting sensitive data is not just about avoiding downtime — it's about ensuring that what is confidential stays that way.

References

Frequently asked questions

What type of ransomware group targeted Cambridge University Press & Assessment?

The ransomware group INC Ransomware targeted the organization, operating through double extortion: it compromises systems, steals data, and threatens to publish it if the ransom is not paid.

What kind of data was published by the ransomware group as proof of the attack?

The group published internal documents on its leak site, including supplier invoices, service contracts, and confidential correspondence.

According to the article, what is the key lesson for managers regarding data protection?

The most serious damage can come from contracts, proposals, invoices, and emails, not just customer databases. Reducing risk starts with visibility and data classification, restricting access, enforcing multi-factor authentication, and monitoring with 24/7 detection and response.

Ransomware Hits the University of Cambridge's Publisher
Kleber Leal by Zamak Portal June 26, 2026
Share this post
Tags
Archive