Quick Summary
AllegedExecutive Summary
Uak University, a state university in Turkey offering higher education across various faculties and departments, was listed on the dark web portal of the Qilin ransomware group on September 2, 2026. This listing was identified by SOCRadar’s Dark Web Monitoring service. The claim of Uak University being a victim has not been independently confirmed. Educational institutions, due to their often extensive digital infrastructure and valuable data, can be attractive targets for ransomware operations. Qilin has been a highly active ransomware group, claiming 243 victims in the preceding 60 days. Their primary targeting has focused on the Manufacturing, Professional Services, and Government & Defense sectors, with a significant majority of these victims located in the United States. Other countries frequently targeted include Germany and Italy. Recent claims by Qilin also list organizations such as Grayson Rural Electric Cooperative (United States, Energy & Utilities), Commission de la construction du Québec (Canada, Government & Defense), Allied Recycling (Ireland, Manufacturing), and Inmac (Argentina, Retail & E-Commerce). The targeting of Uak University represents one of Qilin’s initial claimed attacks within the Turkish education sector during this period, marking a departure from their typical industrial focus.
Technical Analysis
SOCRadar’s analysis of stealer-log data related to usak.edu[.]tr revealed 15 credentials for university-controlled identity and student systems, categorized as Category A. These systems include the university’s Single Sign-On (SSO) and identity platform, student information system, academic management system, class management portal, and institutional internet gateway. Additionally, eight records identified external users accessing the same university-controlled systems (Category B), which could indicate access by students or external partners. The usernames observed followed the numeric-ID format commonly used by Turkish academic institutions. The timestamps of these 26 collected records indicate they were all ingested within a narrow batch window between September 1 and September 2, 2026, directly coinciding with the active intrusion period. Notably, the affected accounts showed no evidence of password rotation within this September 1–2 window, suggesting they remained valid at the time of the credential logging. This timing and batch ingestion are consistent with credential harvesting during an active compromise, potentially facilitating subsequent ransomware deployment. Immediate credential rotation across all affected accounts and the relevant identity infrastructure is recommended as a priority response. Continued dark web monitoring and review of stealer-log feeds should also be maintained.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.