Quick Summary
AllegedExecutive Summary
Cedar Crest College was listed as a victim on the NightSpire ransomware group’s leak portal on July 14, 2026. The college is an education institution located in the US. This incident adds to NightSpire’s victimology, which primarily targets organizations in the United States. SOCRadar’s analysis revealed exposed credentials for the cedarcrest[.]edu domain spanning nearly 20 months, affecting both Microsoft 365 and the college’s internal authentication systems.
Technical Analysis
SOCRadar’s stealer-log data uncovered credentials for the cedarcrest[.]edu domain that were unrotated for nearly 20 months, affecting Microsoft 365 and the college’s internal authentication portals. These credentials covered a wide window, from late November 2024 through mid-July 2026, indicating a significant exposure. The stealer logs contained corporate credentials for Microsoft 365 (login.microsoftonline[.]com), the college’s web authentication (webauth.cedarcrest[.]edu), and student/staff portals (my.cedarcrest[.]edu). The presence of corporate accounts across both Microsoft 365 and external platforms suggests a potential infection on a single workstation. NightSpire, like many ransomware groups, commonly uses infostealer-harvested credentials for initial access by logging into victim systems via Microsoft 365, VPN, or remote access portals before deploying ransomware. Defenders should reset passwords, enforce multi-factor authentication (MFA) on affected accounts, and conduct endpoint forensics on compromised user systems.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.