Quick Summary
AllegedExecutive Summary
The University of the West Indies (UWI), a prominent multi-campus public research university with its headquarters in Trinidad and Tobago and additional campuses across Barbados, Jamaica, and other Caribbean territories, has been listed as a claimed victim by the Qilin ransomware group. The listing appeared on Qilin’s dark web portal on August 17, 2026, and was identified by SOCRadar’s Dark Web Monitoring service. UWI serves tens of thousands of students and staff, making its data a potentially valuable target for ransomware actors. The education sector is not new territory for Qilin, which has previously targeted institutions like Zanichelli, Loescher editore Torino, Université Libre de Bruxelles, and Universitatea de Vest Vasile Goldi din Arad. This claim extends Qilin’s pattern of targeting educational entities into the Caribbean region, a geographic area less frequently associated with the group’s typical operational focus. In the 60 days preceding this listing, Qilin claimed responsibility for 183 other victims, with a significant concentration in the Manufacturing and Professional Services sectors, as well as unclassified targets. The majority of these victims were located in the United States, Germany, and France. The inclusion of the University of the West Indies represents a geographic outlier for Qilin, as listings from the Caribbean and Latin America are uncommon in their operational portfolio. Despite this geographic deviation, the targeting of an educational institution aligns with the ransomware group’s established patterns, suggesting a strategic choice to exploit vulnerabilities within this sector.
Technical Analysis
SOCRadar’s threat intelligence analysis revealed a severe credential exposure related to the University of the West Indies’ infrastructure, specifically targeting the uwi[.]edu domain. A total of twenty-five records were logged across three distinct high-value endpoint clusters, indicating significant exposure. The nature and volume of this exposure suggest a targeted effort rather than incidental data leakage. Further investigation into specific domains identified critical vulnerabilities. Twelve records were logged within a two-second window on August 17, 2026, related to the Banner student information backend (ban.mona.uwi[.]edu:9443). This rapid succession of logging activity is indicative of automated credential harvesting from a compromised endpoint, rather than normal user operations. Additionally, a single employee credential associated with the CAS identity gateway (a.uwi[.]edu/cas/login) was exposed. Compromise of this single sign-on system could grant access to a wide array of integrated UWI systems, significantly increasing the potential impact of a breach. The exposure extends to administrative and ERP panels, including the sas.mona.uwi[.]edu admin panel and the helios1.cavehill.uwi[.]edu ERP backend, along with student and academic portals. Seven external-user credentials and seventeen additional records with institutional identifiers of indeterminate classification were also noted. The correlation of these stealer-log findings with the timing of Qilin’s listing suggests a heightened risk of these credentials being utilized by the ransomware group. While the stealer logs do not definitively confirm that these specific credentials were transmitted to Qilin, the timing and nature of the exposure create a strong correlation, surpassing typical background-level credential exposures. The identified credential exposures, particularly the CAS identity gateway and Banner admin panel access, represent high-value targets for initial access brokers and ransomware operators. Validated credentials for such systems can be leveraged to gain a foothold within an organization’s network, facilitating further lateral movement and eventual ransomware deployment. The immediate priorities for the University of the West Indies should include the revocation of all identified CAS credentials, a thorough audit of the Banner backend access logs, and forensic analysis of the endpoints associated with the August 17 credential cluster to identify the source of the exposure and potential intrusion pathways. Continued monitoring of dark web marketplaces for any further listings or sales of UWI credentials is also advised.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.