An alleged data leak involving Badr University in Cairo (BUC) has been reported on a hacking forum, where a threat actor claims to have obtained access to the university’s database.
According to the forum post, the allegedly exposed information may include:
- National ID numbers
- Home addresses and phone numbers
- Student information
- Parent information
- Administrative data and internal records
The threat actor also shared some administrative records as alleged evidence and claimed to have obtained the university website’s “complete” data.
However, the claim has not been independently confirmed. At this stage, there is no verified evidence establishing that the university was breached, that the data belongs to BUC, or that the full amount of information claimed by the threat actor was actually obtained.
Why the Claim Still Matters
Even an unverified data-leak claim deserves attention because, if the information were genuine, exposed personal details could be used in targeted social-engineering attacks.
For example, an attacker who knows a student’s name, university, phone number, and family information could use those details to make a phishing message or phone call appear legitimate.
Students, parents, faculty, and staff should therefore remain cautious:
- Do not trust a message or phone call simply because the sender knows personal information.
- Never share an OTP, password, or photo of your national ID in response to an unexpected request.
- Never provide banking or payment information through an unsolicited message or call.
- If you reuse your university password on other services, change it immediately and use a unique password.
- If someone contacts you claiming to represent the university, verify the request through an official university channel before taking any action.
Universities should also investigate such claims promptly, preserve relevant evidence, and communicate clearly with affected individuals if a breach is confirmed.
At present, the reported BUC incident should be treated as an allegation rather than a confirmed data breach. Further verification is required to establish the authenticity, source, and scope of the allegedly exposed information.
