A ransomware group calling itself Direwolf claims to have carried out an attack on Arizona State University (ASU), with the claim dated August 17, 2026. This claim appears on the group’s own leak-site listing, which is tracked by ransomware.live, a security research platform that monitors ransomware groups’ public extortion sites. At this time, the claim is unverified — it has not been confirmed by ASU, and no regulator has publicly acknowledged an incident involving the university.
What we know — and don’t
- A group calling itself Direwolf listed Arizona State University on its leak site, with a claimed date of August 17, 2026.
- ASU operates in the education sector, encompassing student, faculty, and administrative systems, among other functions.
- The specific types of data the group claims to have obtained — if any — have not been disclosed in the listing and have not been independently confirmed.
- Arizona State University has not issued a public statement confirming or denying this claim as of this writing.
- No regulatory filing or breach notification tied to this claim has been identified at this time.
What should you do if you have an account with this company?
- Change your password for any ASU-related account, and avoid reusing that password on other sites.
- Enable two-factor authentication (2FA) wherever it is offered, particularly for university portals, email, and financial aid systems.
- Be cautious of unexpected emails, texts, or calls referencing ASU, financial aid, or account verification — these may be phishing attempts that exploit the uncertainty around this claim.
- Monitor your bank and credit card statements for any unfamiliar activity.
- Consider using an identity monitoring service like a service like Aura or LifeLock to help spot signs of misuse of your personal information.
- Keep an eye on official communications directly from ASU rather than relying solely on third-party reports.
BreachLetter will update this page if Arizona State University confirms this incident, issues a public statement, or if the matter is officially reported to regulators.