Alleged Data Leak Claims Target 6 Egyptian Public Universities

Reports of a potential data leak involving six Egyptian public universities have raised concerns over the possible exposure of sensitive personal, academic, and administrative information

The universities named in the claim are Benha University, Helwan University, Cairo University, Kafr El Sheikh University, South Valley University, and Sadat City University.

According to the threat actor, the alleged dataset contains 7,761,608 records across 87 tables. The claimed information may include names, email addresses, phone numbers, national ID numbers, dates of birth, academic and employment information, login records, IP addresses, and, if genuine, plaintext passwords.

The post also claims to contain approximately 1.9 million email records, along with student, staff, and passport-related information.

More concerning is the claim that more than 100,000 scanned documents could be released. These reportedly include national ID documents, birth certificates, payment receipts, and student photographs.

The claims have not been independently verified. At this stage, the authenticity of the data, its source, and the full scope of the alleged exposure remain unconfirmed.

If genuine, the combination of personal, academic, and account-related information could increase the risk of phishing, identity theft, impersonation, targeted scams, and attempts to access online accounts.

Recommended Precautions

Students, graduates, and employees associated with the named universities should consider taking precautionary steps:

  • Change university account passwords immediately, particularly if passwords may have been reused on other services.
  • Change reused passwords on other accounts and use unique passwords.
  • Be cautious of calls, messages, or emails claiming to come from a university, bank, or government organization.
  • Never share passwords, verification codes, or sensitive personal information, and do not transfer money in response to unexpected requests.
  • Avoid clicking links asking you to update university or personal information unless their legitimacy has been independently confirmed.
  • Enable two-step verification on important accounts wherever available.

The incident highlights the importance of treating unverified breach claims seriously while avoiding the spread of unconfirmed information. Organizations and affected individuals should rely on verified information and official communications when assessing the situation.