Scotland's university procurement center confirms cybercrooks broke in
- ID
- 9571
- Status
- summarized
- Published
- 31 Jul 2026, 6:45 PM
- Fetched
- 31 Jul 2026, 7:44 PM
- Provider
- The Register
- Category
- technology
- Original URL
- https://www.theregister.com/cyber-crime/2026/07/31/scotlands-university-procurement-center-confirms-cybercrooks-broke-in/5281654
- Source URL
- https://www.theregister.com/headlines.atom
Summary
- Score
- 4.5
- Created
- 31 Jul 2026, 7:48 PM
- Tags
- Audience
- developerssaas_founders
What happened
Scotland's Advanced Procurement for Universities and Colleges (APUC) confirmed attackers gained unauthorized access to historical data in a mid-July intrusion, which was immediately contained. Sources told The Register the crooks claimed to have stolen 20 years of data and gained admin access through an employee account, with an extortion demand reportedly made—though APUC did not confirm those details and has not appeared on any major ransomware leak sites.
Why it matters
If the employee-account-to-admin-access vector is confirmed, it's another concrete reminder that centralized procurement platforms with decades of retained supplier and institutional data are high-value targets where a single compromised credential can expose long-tail historical records. Builders running shared platforms or aggregators should scrutinize whether old data still needs to be online and whether admin roles are gated behind more than a single login.
Discussion angle
The reported vector—admin access via one employee account—raises the question of whether your own platform's admin roles require MFA, session limits, or just-in-time elevation, and whether 20-year-old data is still sitting in a queryable production system.