A threat actor leaked over 50,000 University of Lagos student records on a dark web forum, exposing names, matric numbers, email addresses, phone numbers and academic results.
A threat actor using the handle "ng_leaker" posted a database dump on a popular dark web forum containing records of over 50,000 University of Lagos students. The data was reportedly extracted from the university's student information portal.
The leaked database contains student full names and matric numbers, personal email addresses and phone numbers, home addresses, academic transcripts and CGPA records, course registration details, and in some cases, passport photographs.
Cybersecurity researchers who analyzed the leak suggest the attacker exploited an unpatched SQL injection vulnerability in the student portal's login page, a basic vulnerability that has been well-documented for decades.
UNILAG management acknowledged the breach in a press release, stating that they are "investigating the matter with relevant authorities" and have temporarily taken the student portal offline for security patching.
With matric numbers, names and academic records exposed, affected students face risks of academic fraud, identity theft, and targeted phishing attacks — particularly during NYSC mobilization and job application periods.
Step-by-step guide
Step 1 — Check your exposure
Visit haveibeenpwned.com and enter your school email to see if your data has appeared in known breaches.
Step 2 — Secure your accounts
Change passwords on your student portal, Gmail, and any platform using the same email.
Step 3 — Alert employers
If you are job hunting, be aware that scammers may contact you with fake offers using your academic data.
Original source
Techpoint Africa
Share this article
No community notes yet
Be the first to add a technical insight.