Quick Summary
AllegedExecutive Summary
AuditTeam listed Vellore Institute of Technology (VIT) on its dark web portal on September 22, 2026. VIT is one of India’s largest private universities, with campuses serving tens of thousands of domestic and international students across engineering, technology, and science programs. The listing was identified through SOCRadar’s Dark Web Monitoring service. In the 60 days prior to this listing, AuditTeam claimed 33 other victims, primarily in Russia, South Korea, and Italy, with a focus on the Technology and Education sectors. Recent listings include Daegu University and other partially redacted entities. VIT represents a high-profile addition to AuditTeam’s pattern of targeting large academic institutions, particularly in Asia.
Technical Analysis
SOCRadar’s stealer-log telemetry returned 25 records for vit.ac[.]in, all dated September 22, 2026, within an approximately two-hour window on the same day as the ransomware portal listing. These records correlate with student-facing portals: VTOP (vtop.vit.ac[.]in), VITEEE (viteee.vit.ac[.]in), vConnect (vconnect.vit.ac[.]in), and the admissions results portal (admissionresults.vit.ac[.]in). The majority of these records appear to be student and applicant accounts in alphanumeric format. While the precise timing does not definitively prove that AuditTeam utilized these specific credentials, the simultaneous occurrence and the absence of prior captures warrant elevated attention. The collection of student and applicant data from these portals, which contain admissions records, academic credentials, and student identity information, highlights a significant potential risk. Treat all 25 exposed portal accounts as compromised. Review access logs on VTOP, VITEEE, vConnect, and admissionresults for unauthorized sessions on and after September 22, 2026. Given the student-account profile, VIT’s security team should also assess whether these credentials were used to pivot toward administrative systems behind the student-facing portals.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.