Quick Summary
AllegedExecutive Summary
The University of Delhi (DU), one of India’s largest and most prominent public universities, has been listed as a victim on the DYSPHOR1A ransomware group’s dark web portal, published on August 20, 2026. The listing was identified through SOCRadar’s Dark Web Monitoring service. Founded in 1922, the University of Delhi serves hundreds of thousands of students across dozens of affiliated colleges in the Indian capital. This listing places one of Asia’s flagship academic institutions under DYSPHOR1A’s claimed victim portfolio. In the 60 days prior to this listing, DYSPHOR1A has claimed 5 other victims across its leak portal. The group has demonstrated a clear focus on Asian educational, governmental, and financial sector organizations across India, Myanmar, Indonesia, the Philippines, and Thailand. Other recent DYSPHOR1A listings include GUSTO College GLMS, Job Net .COM.MM, Indonesian Police Database, and AYUDHYA TH Insurance. The targeting of the University of Delhi is consistent with DYSPHOR1A’s regional pattern, though the organization’s scale makes this among the group’s highest-profile claimed victims.
Technical Analysis
Initial-access correlation against SOCRadar’s stealer-log telemetry surfaced a severe exposure for the du.ac.in domain. The queried sample returned 25 credentials targeting student-facing and admission portal infrastructure associated with the University of Delhi. Log dates on recovered records run to August 21, 2026 — the day immediately following the ransomware listing — indicating that credential exposure from the DU domain is current and active. The dominant profile is consistent with student and applicant-side access to university portals rather than direct administrative or faculty credential compromise, but the volume and recency of exposure warrants investigation across all authentication systems. For ransomware groups such as DYSPHOR1A, infostealer-harvested credentials are a well-documented initial access vector: operators or initial access brokers source fresh logs from underground marketplaces, validate the credentials, and use them to log into VPN, student portals, or remote-access platforms before deploying ransomware or exfiltrating data. While the stealer-log evidence here does not confirm that these specific credentials were used by DYSPHOR1A, the current and active student-facing credential exposure across a major national university’s domain represents a meaningful risk surface. CTI teams and university IT security should prioritize audit of privileged access systems, faculty and staff accounts, and administrative infrastructure separate from the student portal footprint.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.