Quick Summary
AllegedExecutive Summary
EndZone listed Philander Smith University on its dark web portal on October 6, 2026. This listing was identified through SOCRadar’s Dark Web Monitoring service. Philander Smith University is a private historically Black liberal arts institution located in Little Rock, Arkansas, offering undergraduate and graduate programs. The university focuses on academic excellence, social justice, and community leadership development, operating under the domain philander[.]edu. This incident marks a sector shift for EndZone, as their prior listings were predominantly within the Technology and Professional Services industries. This appears to be the group’s first known targeting of the education sector within the current 60-day observation window. Educational institutions are often targeted due to the significant volumes of sensitive personal and research data they hold, coupled with historically under-resourced security operations.
Technical Analysis
SOCRadar’s telemetry returned five credentials associated with the domain philander[.]edu. Two of these credentials were classified as category A, indicating direct employee authentication hits against the university’s Duo Security Multi-Factor Authentication (MFA) endpoint. This is a critical identity control mechanism. An additional three credentials were category C, signifying corporate-domain credentials that were exfiltrated alongside data from third-party services, indicative of infected endpoints. The identified high-value services involved in the data exfiltration include the Duo Security MFA portal, Google’s identity provider (accessed using university-domain credentials), and a third-party academic learning platform. The telemetry data indicates a freshness window for these credentials ranging from August 12 to October 1, 2026, suggesting these are live-range credentials rather than outdated information. The presence of two separate hits on the Duo MFA endpoint, occurring in August and September 2026, aligns with the common pre-ransomware credential validation pattern, where threat actors test the validity of stolen login information against critical identity layers. While this stealer-log data does not confirm that EndZone successfully used these credentials for access, it does confirm the existence of compromised credentials and that the MFA gateway has been targeted. Given these findings, response teams should treat the five identified accounts as potentially compromised. It is recommended to prioritize a Duo Security audit and enforce forced password resets for these accounts. Additionally, endpoint forensics should be conducted on machines associated with the category C records to identify any further signs of compromise or lateral movement. Continued monitoring of dark web stealer-log feeds and proactive credential hygiene checks, including password rotation and MFA review, are advised.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.